Core Security Technologies has found a means of bypassing the authentication system to the Web management interface in Axis network video cameras. Using a double slash (“//”) after the camera’s IP address in a URL will drop the user directly into the Web interface without being asked for a password. More information about the vulnerability as well as links to the appropriate firmware upgrades can be found here.
Authentication flaw found in Axis cameras
Opinion
May 29, 20031 min




