CVE-2020-9529
CRITICALShenzhen Hichip Vision Technology Firmware < 2020-06-29 - Privilege Escalation via Administrator Password Reset
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-9529. PoCs published by prisect.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2020-9529, which targets a vulnerability in Hichip IP cameras allowing an attacker to reset the admin password via a crafted UDP message. The exploit includes discovery and reset functionality, demonstrating the vulnerability effectively.
Description
Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions of Internet of Things devices, suffers from a privilege escalation vulnerability that allows attackers on the local network to reset the device's administrator password. This affects products marketed under the following brand names: Accfly, Alptop, Anlink, Besdersec, BOAVISION, COOAU, CPVAN, Ctronics, D3D Security, Dericam, Elex System, Elite Security, ENSTER, ePGes, Escam, FLOUREON, GENBOLT, Hongjingtian (HJT), ICAMI, Iegeek, Jecurity, Jennov, KKMoon, LEFTEK, Loosafe, Luowice, Nesuniq, Nettoly, ProElite, QZT, Royallite, SDETER, SV3C, SY2L, Tenvis, ThinkValue, TOMLOV, TPTEK, WGCC, and ZILINK.
Exploits (1)
This repository contains a functional exploit for CVE-2020-9529, which targets a vulnerability in Hichip IP cameras allowing an attacker to reset the admin password via a crafted UDP message. The exploit includes discovery and reset functionality, demonstrating the vulnerability effectively.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H