PLANEX CS-QP50F-ING2 Smart Camera Remote Configuration Disclosure
Vulnerability Description
PLANEX CS-QP50F-ING2 smart cameras expose a configuration backup interface over HTTP that does not require authentication. A remote, unauthenticated attacker can directly retrieve a compressed configuration backup file from the device. The backup contains sensitive configuration information, including credentials, allowing an attacker to obtain administrative access to the camera and compromise the confidentiality of the monitored environment.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-4468
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Todor Donev
Affected Vendor
PLANEX COMMUNICATIONS Inc.
View all reports →