Description
Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a remote control service without using any encryption. This enables an on-path attacker to eavesdrop the credentials and subsequently obtain access to the video stream.
The credentials are being sent when a user decides to change his password in router's portal.
The credentials are being sent when a user decides to change his password in router's portal.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46811 | Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a remote control service without using any encryption. This enables an on-path attacker to eavesdrop the credentials and subsequently obtain access to the video stream. The credentials are being sent when a user decides to change his password in router's portal. |
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2024-08-01T21:18:06.842Z
Reserved: 2024-06-04T14:42:02.523Z
Link: CVE-2024-5631
Updated: 2024-08-01T21:18:06.842Z
Status : Deferred
Published: 2024-07-09T11:15:15.740
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-5631
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD