Storm on the Horizon: Inside the AJCloud IoT Ecosystem
ID: ad0615e1-9062-5f71-b56d-374ce0c425f5
STIX ID: report--ad0615e1-9062-5f71-b56d-374ce0c425f5
Feed Name: Elastic Security Labs
Researchers analyzed AJCloud-based Wi‑Fi cameras (e.g., Wansview Q5/Q6), discovered critical access-control and P2P protocol flaws that allow unauthenticated remote access to video/audio and device control by substituting a deviceId, and implemented PoC exploits (including a P2P client) that can remotely control, brick devices by corrupting a configuration INI, and potentially achieve remote code execution via a buffer overflow; the issues affect multiple vendors and millions of deployed devices and vendor disclosure attempts failed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
