CVE-2019-25248

7.5

Beward · N100 H.264 VGA IP Camera

The Beward N100 camera contains an unauthenticated vulnerability allowing remote attackers to access live RTSP video streams without valid credentials.

Executive summary

A critical authentication bypass vulnerability in Beward N100 IP cameras allows unauthenticated remote attackers to view live video feeds, posing a significant privacy and security risk.

Vulnerability

The device suffers from a missing authentication for critical function (CWE-306) vulnerability, which allows any unauthenticated attacker to retrieve the RTSP stream by accessing the device directly. The vulnerability resides in the video access mechanism, specifically via the cgi-bin/view/image endpoint.

Business impact

The ability for unauthorized parties to access live video surveillance feeds presents a severe privacy violation and potential physical security risk. Given the CVSS score of 7.5, this high-severity flaw enables remote surveillance of sensitive areas without any requirement for user interaction or administrative privileges, potentially leading to unauthorized reconnaissance of protected facilities.

Remediation

Immediate Action: As no official patch is currently identified for this legacy device, immediately isolate the affected camera from the public internet by placing it behind a firewall or within a restricted management VLAN.

Proactive Monitoring: Monitor network traffic for unauthorized access attempts to the device web interface and specifically audit logs for connections directed toward the RTSP streaming ports or the identified vulnerable CGI path.

Compensating Controls: Deploy a Web Application Firewall or a network-level access control list to block unauthorized requests to the camera's management and streaming endpoints.

Exploitation status

Public Exploit Available: Yes, a public exploit is available via the Exploit-DB entry 46317.

Analyst recommendation

Due to the sensitive nature of video surveillance data and the availability of public exploits, this vulnerability poses a high risk to physical security and privacy. Administrators should prioritize network isolation of the affected Beward units immediately and evaluate the necessity of replacing legacy hardware that lacks vendor-provided security updates.

More Beward CVEs

Sources

Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.