Site icon TheCyberThrone

Camera 📷 can Eavesdrop

Advertisements

Millions of connected security and home cameras contain a critical software vulnerability that can allow remote attackers to tap into video feeds that goes wild warns CISA.

The bug (CVE-2021-32934, with a CVSS v3 base score of 9.1) has been introduced via a supply-chain component from ThroughTek that’s used by several original equipment manufacturers (OEMs) of security cameras along with makers of IoT devices through which video feeds can be viewed paving way for potential attacks and privacy will be in a big question

P2P SDK

The ThroughTek component at issue is its P2P SDK installed in several million connected devices, It’s used to provide remote access to audio and video streams over the internet.

Nozomi Networks, which discovered the bug, noted that the way P2P works is based on three architectural aspects:

Affected Versions and Remedies:

Actions to Take:

IoT camera bugs are hardly rare: Last month, for instance, owners of Eufy home-security cameras warned of an internal server bug that allowed strangers to view, pan and zoom in on their home-video feeds. Customers were also suddenly given access to do the same to other users.

Exit mobile version