S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-40150 Scanner

Detects 'Information Disclosure' vulnerability in E1 Zoom camera affects v. through 3.0.0.716.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-40150
7.5
CVSS

The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly accessible path. In this way an attacker can download the entire NGINX/FastCGI configurations by querying the /conf/nginx.conf or /conf/fastcgi.conf URI.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The E1 Zoom camera is a cutting-edge surveillance device that provides full HD resolution and remote live viewing through the user's mobile phone. This camera is a top-rated product for commercial and residential safety purposes. It is popular due to its easy installation and maintenance, as well as the various features it offers, such as IR night vision, 355-degree horizontal rotation, two-way audio, and motion detection. 

Recently, a vulnerability was discovered in this camera's web server that can lead to a severe security threat. The CVE-2021-40150 vulnerability allows an attacker to access and download the entire NGINX/FastCGI configuration by querying the /conf/nginx.conf or /conf/fastcgi.conf URI. This means that an attacker can easily gather sensitive information about the camera's configuration, including the login credentials and file paths. 

If this vulnerability is exploited, an attacker can gain full control of the camera's settings and execute arbitrary commands on the device, including deleting or modifying files, stealing data, and even using the camera to launch DDoS attacks against other targets. This can cause major disruptions and pose a significant threat to both individuals and businesses who use these cameras for surveillance purposes. 

In conclusion, it is imperative to stay informed about the latest security vulnerabilities that can affect your digital assets. By utilizing a comprehensive platform such as s4e.io, individuals and businesses can easily and quickly learn about the various security threats that can affect their digital assets. Through this platform, users can access timely information and tips on how to protect their devices and data against emerging threats and vulnerabilities. Don't risk your security, stay informed, and take the necessary precautions to protect your digital assets.

 

REFERENCES

Solution Advice

To avoid becoming a victim of this security threat, the following precautions can be taken:

  • Immediately update the firmware of the E1 Zoom camera to the latest version that addresses this vulnerability.
  • Limit exposure of the camera’s web server to the public network by either connecting it to a VPN or utilizing a firewall.
  • Change the default login credentials to a strong password to prevent unauthorized access.
  • Monitor the camera's activity logs regularly and investigate any suspicious login attempts.
  • Continuously monitor the latest vulnerabilities associated with the E1 Zoom camera and apply necessary patches as soon as they become available.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.