CVE-2024-5633
Description
Longse model LBH30FE200W cameras, as well as products based on this device, provide an unrestricted access for an attacker located in the same local network to an undocumented binary service CoolView on one of the ports. An attacker with a knowledge of the available commands is able to perform read/write operations on the device's memory, which might result in e.g. bypassing telnet login and obtaining full access to the device.
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2024-5633? +
How do I check if I'm vulnerable to CVE-2024-5633? +
Related Vulnerabilities
The "update" binary in the firmware of the affected product sends attempts to mount to a hard-coded, routable IP address, …
A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 …
An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not …
Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized …
A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of network packets …
Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.