#VU31893 Weak password requirements in HD838 and HD438IR - CVE-2020-11624
Published: July 27, 2020
HD838
HD438IR
AvertX
Description
The vulnerability allows a remote attacker to perform brute-force attack and guess the password.
The vulnerability exists due to the affected cameras do not require users to change the default password for the admin account. A remote authenticated attacker can perform a brute-force attack and disclose the default username within the login.js script.