OT Security, IoT

Two-decade-old vulnerability found in Wansview security camera

Security camera lens

Cyber Insider disclosed that a popular Wansview indoor security camera model, the WVC Q5, was found to be shipping with a web server vulnerable to a flaw first identified over 20 years ago. The vulnerability, CVE-2002-1819, is a directory traversal flaw that allows unauthorized access to files on the device.

Researchers from Finite State discovered the vulnerability in the Wansview WVC Q5, an inexpensive Wi-Fi camera used as a baby monitor, pet camera, and indoor security device. The camera utilizes an AjCloud IoT platform, meaning other brands using the same firmware could also be affected. The flaw allows anyone on the same network to retrieve sensitive information, including administrator credentials and cloud access tokens, by exploiting a specially crafted HTTP request. The default credentials of 'admin:123456' further exacerbate the risk. The analysis also revealed two additional vulnerabilities that could cause the camera's web server to crash or reboot. Although a full remote code execution exploit was not developed, the lack of modern security mitigations suggests exploitation is plausible. The incident highlights weaknesses in the IoT software supply chain, as the vulnerable component persisted due to a lack of inventory tracking and vulnerability scanning by involved parties. Wansview has since released a firmware update (version 01.10715.11.37) that removes the vulnerable web server. However, the security status of other cameras on the same platform remains unclear, prompting recommendations for users to keep IoT devices updated, segment networks, and exercise caution with white-label products.

Source: Cyber Insider

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds