Today > vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-5634

July 9, 2024, 6:19 p.m.

Product(s) Impacted

Longse LBH30FE200W cameras

Description

Longse model LBH30FE200W cameras, as well as products based on this device, make use of telnet passwords which follow a specific pattern. Once the pattern is known, brute-forcing the password becomes relatively easy.  Additionally, every camera with the same firmware version shares the same password.

Weaknesses

CWE-1391
Use of Weak Credentials

The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.

CWE ID: 1391

Date

Published: July 9, 2024, 11:15 a.m.

Last Modified: July 9, 2024, 6:19 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

cvd@cert.pl

References