Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products...
Vulnerability Description
Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a remote control service without using any encryption. This enables an on-path attacker to eavesdrop the credentials and subsequently obtain access to the video stream. The credentials are being sent when a user decides to change his password in router's portal.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-5631
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Adam Zambrzycki
References
More from Longse Technology
View All →Affected Vendor
Longse Technology
View all reports →