Weak password requirements in HD838 and HD438IR - CVE-2020-11624
Published: July 27, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform brute-force attack and guess the password.
The vulnerability exists due to the affected cameras do not require users to change the default password for the admin account. A remote authenticated attacker can perform a brute-force attack and disclose the default username within the login.js script.
Affected software
HD438IR
How to mitigate CVE-2020-11624
HD438IR - update to 5.6.0_200307