logo

Storm on the Horizon: Inside the AJCloud IoT Ecosystem

ID: ad0615e1-9062-5f71-b56d-374ce0c425f5

STIX ID: report--ad0615e1-9062-5f71-b56d-374ce0c425f5

Feed Name: Elastic Security Labs

Threat Score
80/100

Date Published: 2024-09-20

Date Updated: 2026-04-27

...
...

Researchers analyzed AJCloud-based Wi‑Fi cameras (e.g., Wansview Q5/Q6), discovered critical access-control and P2P protocol flaws that allow unauthenticated remote access to video/audio and device control by substituting a deviceId, and implemented PoC exploits (including a P2P client) that can remotely control, brick devices by corrupting a configuration INI, and potentially achieve remote code execution via a buffer overflow; the issues affect multiple vendors and millions of deployed devices and vendor disclosure attempts failed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.