Serious Segurity Bug in NC250

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Serious Segurity Bug in NC250

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Serious Segurity Bug in NC250
Serious Segurity Bug in NC250
2017-07-02 21:11:03
Hello

I contacted with a Techical support 2 Montch ago because I detect a serius Segurity Bug in The NC250 . the answer is very very bad. " We will correct the bug in the future" ... Never being clear.

Today I'm going to make the bug public

Descripcion:

This bug allow view the video and audio without Password or user if you has change the password.

Product Affected:


TP-LINK NC250 V1 and more models its possible

Firmware afected:

1.2.1 build 170515 or less (all version is affected)

Exploit the bug:

1º Conect to Local Network the camera (WIFI or ethernet)
2º Open VLC software in your computer connected to the Local Network and open network URL:
3º Write this rtsp://admin@yourip:554/h264_hd.sdp
4º and play

The system not check the password. Its the same change the password or no.
  0      
  0      
#1
Options
4 Reply
Re:Serious Segurity Bug in NC250
2017-07-03 02:27:41
The same bug has TP-LINK nc450 with latest firmware. I think that all tp-link models are affected.this bug.
  0  
  0  
#2
Options
Re:Serious Segurity Bug in NC250
2017-07-18 17:49:40
i test in on my camera, i still need to login

  0  
  0  
#3
Options
Re:Serious Segurity Bug in NC250
2017-07-19 18:02:12
The RTSP path you use is contain account and password, for example, rtsp://yourip/h264_hd.sdp is the video path. but if you want to login need to input password. When you add some URL for example account and password in your URL rtsp://admin(account):admin(password)@yourip:554/h264_hd.sdp, VLC will play it without login. It is mostly used in website video contribute.

  0  
  0  
#4
Options
Re:Serious Segurity Bug in NC250
2017-07-19 18:02:31
can you show us some screenshot?
  0  
  0  
#5
Options