Unauthenticated RTSP Video Stream Access via ONVIF WebSocket Endpoint
ONVIF RTSP-over-WebSocket endpoint accessible without authentication.
Read the writeup →Vulnerability research, detection engineering, and applied cryptography.
ONVIF RTSP-over-WebSocket endpoint accessible without authentication.
Read the writeup →IPv6-mapped IPv4 (::ffff:127.0.0.1) bypasses the IPv4-only loopback filter on httptest.cgi.
dnsupdate.cgi delete path skips the input validation applied to add.
pingtest.cgi skips the camera's own validateaddr helper.
SNMP community strings returned in the viewer-role config endpoint.
Read the writeup →