old.denver.euproduct
http://old.denver.eu/products/smart-home-security/denver-sho-110/c-1024/c-1243/p-3826 CVE-2021-4469
HIGH
Denver SHO-110 IP Camera Unauthenticated Snapshot Access
Record summary
CVE-2021-4469 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
Denver SHO-110 IP cameras expose a secondary HTTP service on TCP port 8001 that provides access to a '/snapshot' endpoint without authentication. While the primary web interface on port 80 enforces authentication, the backdoor service allows any remote attacker to retrieve image snapshots by directly requesting the 'snapshot' endpoint. An attacker can repeatedly collect snapshots and reconstruct the camera stream, compromising the confidentiality of the monitored environment.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 17, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SHO-110Browse Denver / SHO-110Default status: unknown | CVE List | Version range not supplied | affected |
Proofs of concept
1Catalogued exploits
ExploitDBDenver IP Camera SHO-110 - Unauthenticated SnapshotExploitDB exploitby Ivan NikolskyNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-4469 exploit-db.comexploit
https://www.exploit-db.com/exploits/50162 vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/denver-sho-110-ip-camera-unauthenticated-snapshot-access