CVE-2024-5632

July 9, 2024, 6:19 p.m.

Product(s) Impacted

Longse NVR NVR3608PGE2W

Description

Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, create a WiFi network with a default password. A user is neither advised to change it during the installation process, nor such a need is described in the manual. As the cameras from the same kit connect automatically, it is very probable for the default password to be left unchanged.

Weaknesses

CWE-1392
Use of Default Credentials

The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.

CWE ID: 1392

Date

Published: July 9, 2024, 11:15 a.m.

Last Modified: July 9, 2024, 6:19 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

cvd@cert.pl

References