CVE-2024-5631

CVSS V2 None CVSS V3 None
Description
Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a remote control service without using any encryption. This enables an on-path attacker to eavesdrop the credentials and subsequently obtain access to the video stream.  The credentials are being sent when a user decides to change his password in router's portal.
Overview
  • CVE ID
  • CVE-2024-5631
  • Assigner
  • CERT-PL
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-07-09T10:57:24.256Z
  • Last Modified Date
  • 2024-07-09T20:42:03.582Z
History
Created Old Value New Value Data Type Notes
2024-07-10 13:25:13 Added to TrackCVE