Multiple IoT Vendors – Multiple...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Vulnerabilities summary The following advisory describes three (3) vulnerabilities found in the following vendors: * Lorex * StarVedia * Eminent * Kraun The vulnerabilities found: * Hard-coded credentials * Remote command injection (2) It is possible to chain the vulnerabilities and to achieve unauthenticated remote command execution. ### Credit An independent security researcher, Robert Kugler (https://www.s3cur3.it), has reported this vulnerabilities to Beyond Security’s SecuriTeam Secure Disclosure program. ### Vendor response We tried to contact Lorex, Kraun and Eminent, attempts to establish contact went unanswered, therefore no details have been provided on a solution or a workaround. StarVedia were informed of the vulnerabilities and released patches to address them – “These two issues were fixed before your contacting us” ### Vulnerabilities details Hard-coded credentials Default users that can be used to log in in the router’s website is: “supervisor”, with the...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息