DVR default username and password

Disclosed: 2018-10-15 22:31:22 By radosec To starbucks
Medium
Vulnerability Details
**Summary:** default username and password i found in one of your DVR camera system **Description:** hi after scanning on starbucks register ip from this site http://bge.he.net i start to scan the ip subnet : ████ then i found this ip : █████ then i try to browse it then i found login page for DVR cam system as can see in this picture : F337222 then i start to test the default username and password like user -- user then i successfully login to your dvr system and browse you cams as i show in this photo : F337223 ## Steps To Reproduce: 1. scanning in this ip subnet ███████ and found █████████ 2. browse ███████ and i found web client for DVR system 1. login by default username and password username : user --- password : user ## Impact an attacker can control your DVR system and changing setting .. etc
Actions
View on HackerOne
Report Stats
  • Report ID: 398797
  • State: Closed
  • Substate: resolved
  • Upvotes: 21
Share this report