Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
- Akuvox Smart Intercom/Doorphone Unauthenticated Stream Disclosure[6]
- Authored by LiquidWorm[7] | Site zeroscience.mk[8]
-
Akuvox Smart Intercom/Doorphone suffers from an unauthenticated live stream disclosure when requesting video.cgi endpoint on port 8080. Many versions are affected.
- SHA-256 |
b9109fbd6b81561f43a64e422162fa5e99ed650e66b857057e94fc3b868986d0 - Download[9] | Favorite[10] | View[11]
Change Mirror[12] Download[13]
Akuvox Smart Intercom/Doorphone Unauthenticated Stream Disclosure
Vendor: The Akuvox Company
Product web page: https://www.akuvox.com
Affected version: Doorphone:
S539
S532
X916
X915
X912
R29
Intercom:
R20K-2
R20A-2
C313W-2
NS-2
NC-2
NX-2
Firmware: 912.30.1.137
Summary: Vandal-resistant Door Phone for High-end Buildings. Offering
top-of-the-line features, Akuvox X912 is targeted at high-end residential
and commercial projects. With a compact size, it is perfect for buildings
with limited installation space.
Desc: The application suffers from an unauthenticated live stream disclosure
when requesting video.cgi endpoint on port 8080.
Tested on: lighttpd/1.4.30
EasyHttpServer
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience
Advisory ID: ZSL-2024-5826
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2024-5826.php
25.02.2024
--
$ firefox http://192.168.1.2:8080/video.cgi
File Tags
- ActiveX[19] (933)
- Advisory[20] (86,478)
- Arbitrary[21] (16,888)
- BBS[22] (2,859)
- Bypass[23] (1,867)
- CGI[24] (1,034)
- Code Execution[25] (7,825)
- Conference[26] (691)
- Cracker[27] (844)
- CSRF[28] (3,401)
- DoS[29] (25,095)
- Encryption[30] (2,389)
- Exploit[31] (53,242)
- File Inclusion[32] (4,263)
- File Upload[33] (997)
- Firewall[34] (822)
- Info Disclosure[35] (2,891)
- Intrusion Detection[36] (916)
- Java[37] (3,144)
- JavaScript[38] (899)
- Kernel[39] (7,225)
- Local[40] (14,800)
- Magazine[41] (587)
- Overflow[42] (13,172)
- Perl[43] (1,435)
- PHP[44] (5,225)
- Proof of Concept[45] (2,394)
- Protocol[46] (3,727)
- Python[47] (1,646)
- Remote[48] (31,674)
- Root[49] (3,638)
- Rootkit[50] (527)
- Ruby[51] (632)
- Scanner[52] (1,657)
- Security Tool[53] (8,029)
- Shell[54] (3,277)
- Shellcode[55] (1,217)
- Sniffer[56] (902)
- Spoof[57] (2,278)
- SQL Injection[58] (16,614)
- TCP[59] (2,441)
- Trojan[60] (690)
- UDP[61] (904)
- Virus[62] (670)
- Vulnerability[63] (33,006)
- Web[64] (9,968)
- Whitepaper[65] (3,782)
- x86[66] (967)
- XSS[67] (18,260)
- Other[68]
File Archives
- August 2024[69]
- July 2024[70]
- June 2024[71]
- May 2024[72]
- April 2024[73]
- March 2024[74]
- February 2024[75]
- January 2024[76]
- December 2023[77]
- November 2023[78]
- October 2023[79]
- September 2023[80]
- Older[81]
Systems
- AIX[82] (429)
- Apple[83] (2,099)
- BSD[84] (377)
- CentOS[85] (58)
- Cisco[86] (1,927)
- Debian[87] (7,102)
- Fedora[88] (1,693)
- FreeBSD[89] (1,246)
- Gentoo[90] (4,567)
- HPUX[91] (880)
- iOS[92] (378)
- iPhone[93] (108)
- IRIX[94] (220)
- Juniper[95] (69)
- Linux[96] (50,834)
- Mac OS X[97] (691)
- Mandriva[98] (3,105)
- NetBSD[99] (256)
- OpenBSD[100] (489)
- RedHat[101] (16,581)
- Slackware[102] (941)
- Solaris[103] (1,611)
- SUSE[104] (1,444)
- Ubuntu[105] (9,760)
- UNIX[106] (9,439)
- UnixWare[107] (187)
- Windows[108] (6,674)
- Other[109]
- Services
- Security Services[120]
- Hosting By
- Rokasec[121]


