Showing 1 vulnerability on this page for ipm-721s_firmware

Signals CISA KEV Ransomware Nuclei
Amcrest vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Amcrest ipm-721s_firmware Use of Hard-coded Credentials

Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reverses the firmware to identify them. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable function that sets up the d

CWE-798Jul 3, 2019
CVSS9.8v3.0EPSS3.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX