Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:22673
HistoryOct 22, 2009 - 12:00 a.m.

Everfocus EDR1600 remote authentication bypass

2009-10-2200:00:00
vulners.com
71

Product: Everfocus EDR1600
Version affected: all
Website: http://www.everfocus.com/
Discovered By: Andrea Fabrizi
Email: [email protected]
Web: http://www.andreafabrizi.it
Vuln: remote DVR authentication bypass


The EDR1600 firmware don't handle correctly users authentication and sessions.

This exploit let you to connect to every remote DVR (without username
and password) and see the live cams :)

Exploit: http://www.andreafabrizi.it/files/EverFocus_edr1600_Exploit.tar.gz