CVE-2021-47796

Denver · SHC-150 Smart Wifi Camera

The Denver SHC-150 Smart Wifi Camera contains hard-coded credentials for the telnet service, enabling unauthenticated remote attackers to execute arbitrary commands on the operating system.

Executive summary

A critical hard-coded credential vulnerability in the Denver SHC-150 Smart Wifi Camera allows unauthenticated remote attackers to achieve full system compromise via arbitrary command execution.

Vulnerability

The device uses hard-coded credentials for the telnet service (CWE-798), which is accessible over the network without authentication. This allows attackers to gain shell access and execute commands with elevated privileges.

Business impact

Successful exploitation grants an attacker full control over the camera, which can be used to pivot into the local network, intercept video feeds, or participate in botnet activities. With a CVSS score of 9.8, this represents an extreme risk to both the physical site security and the overall integrity of the internal network.

Remediation

Immediate Action: Disable the telnet service on the device immediately if possible; if no official patch is available, replace the hardware or isolate it from the internet via a firewall.

Proactive Monitoring: Inspect network logs for unauthorized connections to port 23 and monitor for unusual outbound traffic originating from the camera.

Compensating Controls: Place the device on an isolated VLAN with strict ingress and egress filtering to prevent unauthorized external access.

Exploitation status

Public Exploit Available: Yes — a public exploit is available via ExploitDB (ID: 50160).

Analyst recommendation

Given the existence of a public exploit and the lack of a clear vendor patch path, this device should be considered high-risk. We strongly recommend immediate network isolation or decommissioning of the affected SHC-150 units to prevent potential unauthorized access.