Security Advisory

CVE-2019-10710

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-04-23 19:06:47
Last updated 2024-08-04 22:32:01
Assigner mitre
State PUBLISHED

Description

Insecure permissions in the Web management portal on all IP cameras based on Hisilicon Hi3510 firmware allow authenticated attackers to receive a networks cleartext WiFi credentials via a specific HTTP request. This affects certain devices labeled as HI3510, HI3518, LOOSAFE, LEVCOECAM, Sywstoda, BESDER, WUSONGLUSAN, GADINAN, Unitoptek, ESCAM, etc.