logo

Technical Advisory: Gaining root access on Sumpple S610 IP Camera via Telnet; and Unprotected client and server data transmission between Android and IOS clients

ID: 20c6d9ac-2ef1-58a7-9077-39cc4b47c443

STIX ID: report--20c6d9ac-2ef1-58a7-9077-39cc4b47c443

Feed Name: NCC Research

Threat Score
70/100

Date Published: 2025-12-02

Date Updated: 2026-08-01

...
...

This NCC Group advisory (published 2019-11-28) details CVE-2019-12085 and CVE-2019-16727 affecting Sumpple S610 IP cameras and the Sumpple IP Cam mobile app: firmware images expose /etc/passwd with descrypt/md5crypt hashes that can be trivially cracked, an undocumented Telnet service allows root login (port 23 open), and the mobile app transmits credentials in base64 over HTTP enabling MITM interception and account/camera takeover; recommended mitigations include blocking TCP ports 23/80 and using VPNs or cellular connectivity for app access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.