Longse model LBH30FE200W cameras, as well as products based on this device, make use of telnet passwords which follow a specific pattern. Once the pattern is known, brute-forcing the password becomes relatively easy. Additionally, every camera with the same firmware version shares the same password.
The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.
Link | Tags |
---|---|
https://zamel.com/pl/gardi/zestaw-monitoringu-bezprzewodowego-wi-fi-typ-zmb-01 | product |
https://cert.pl/en/posts/2024/07/CVE-2024-5631/ | third party advisory |
https://cert.pl/posts/2024/07/CVE-2024-5631/ | third party advisory |