S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Mar 19, 2026

Brickcom Camera Unauthenticated Access Scanner

This scanner targets the ONVIF media endpoint on Brickcom cameras, allowing attackers to retrieve snapshots without authentication.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
Detail

Brickcom Camera is a product line known for its IP cameras that are employed across various industries for surveillance purposes. These cameras are used in households, businesses, and public places to ensure security and monitor activities. Used globally, Brickcom cameras rely on robust network connections to deliver real-time video feeds. They offer features like real-time monitoring, remote access, and integration with other security systems. These cameras serve critical roles in environments requiring extensive surveillance and security. Therefore, ensuring the privacy and security of the video feeds they produce is of utmost importance.

The vulnerability identified involves unauthenticated access to Brickcom Camera's media endpoints. Exploiting it allows unauthorized users to retrieve camera snapshots without needing credentials. This issue primarily affects configurations exposing the ONVIF protocol, often overlooked in default settings. The vulnerability arises from insufficient access controls on the snapshot endpoint, which fails to verify user identity before granting access to sensitive visual data.

Specifically, the vulnerable endpoint is the ONVIF media service URL, typically accessible via HTTP on port 80 or 8080. The parameter 'SnapshotUri' in the GetSnapshotUri request is exposed without authentication, allowing attackers to directly fetch JPEG images from the camera's live feed. This endpoint is often left unsecured in default configurations, especially when cameras are deployed without proper network segmentation.

If exploited, an attacker can gain unauthorized access to live camera snapshots, leading to privacy violations and potential surveillance of sensitive areas. This can compromise security in environments like homes, offices, or public spaces, enabling malicious activities such as spying or reconnaissance. The impact is heightened in critical infrastructure settings where visual data is confidential.

Solution Advice
  • Enable authentication on all ONVIF media endpoints to require valid credentials for snapshot access.
  • Update Brickcom camera firmware to the latest version to patch known vulnerabilities.
  • Restrict network access to camera feeds using firewalls or VLANs to limit exposure to trusted IPs.
  • Disable unnecessary services like ONVIF if not required, or configure them with strong passwords.
  • Conduct regular security audits to verify that snapshot endpoints are not publicly accessible.
  • Implement HTTPS encryption for all camera communication to prevent interception of credentials.
  • Use network monitoring tools to detect unauthorized access attempts to camera endpoints.
  • Apply the principle of least privilege by granting camera access only to authorized users and systems.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.