S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 18, 2024

CVE-2017-8229 Scanner

CVE-2017-8229 scanner - Credential Disclosure vulnerability in Amcrest IP Camera Web Management

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-8229
9.8
CVSS

Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable function that sets up the default credentials on the device. If one opens this binary in IDA-pro one will notice that this follows a ARM little endian format. The function sub_436D6 in IDA pro is identified to be setting up the configuration for the device. If one scrolls to the address 0x000437C2 then one can see that /current_config is being set as an ALIAS for /mnt/mtd/Config folder on the device. If one TELNETs into the device and navigates to /mnt/mtd/Config folder, one can observe that it contains various files such as Account1, Account2, SHAACcount1, etc. This means that if one navigates to http://[IPofcamera]/current_config/Sha1Account1 then one should be able to view the content of the files. The security researchers assumed that this was only possible only after authentication to the device. However, when unauthenticated access tests were performed for the same URL as provided above, it was observed that the device file could be downloaded without any authentication.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

Amcrest IPM-721S V2.420.AC00.16.R.20160909 is a popular device used for home surveillance, which is controlled through an online interface. This device enables people to check their homes from remote locations, using the Internet as a medium. Unfortunately, this device incorporates a critical vulnerability detected by security researchers, known as CVE-2018-19287.

CVE-2018-19287 is a vulnerability that can be found in the Amcrest IPM-721S V2.420.AC00.16.R.20160909 device. This vulnerability was detected by security researchers who pointed out that anyone can download the administrative credentials without authentication. The vulnerability is caused by a binary file named "sonia," which configures the device's default credentials. The vulnerability is present in the ARM little endian format, which makes it easy to be exploited.

When CVE-2018-19287 vulnerability is exploited in the Amcrest IPM-721S V2.420.AC00.16.R.20160909 home surveillance device, it can lead to unauthorized access to people's private and sensitive information. The vulnerability allows anyone with access to the device to download the administrative credentials without any need for authentication. As a result, this makes it possible for malicious actors to gain access to private information, such as login information, password details, and other sensitive data.

s4e.io is an online platform known for detecting and reporting vulnerabilities in digital assets like home surveillance devices, web applications, mobile apps, and more. With the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets by subscribing to their online security feeds. This ensures that users can stay up-to-date with the latest security vulnerabilities and patches, reducing their chances of being hacked.

 

REFERENCES

Solution Advice

To protect against the CVE-2018-19287 vulnerability, some precautionary measures can be taken, including:

  • Updating the device's firmware to the latest version, as it contains the latest security updates and patches.
  • Changing the password and login details immediately after the device is connected to the Internet.
  • Avoiding using default passwords, as this makes hacking easier.
  • Restricting access to the device by changing the settings to only allow trusted users to connect to the device.
  • Regularly monitoring the device's activity logs to check for any suspicious or unwarranted activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-8229 scanner - Credential Disclosure vulnerability in Amcrest IP Camera Web Management | S4E