Responsible Disclosure: Ouvis C2 HD Security Camera
ID: 9c3c64f0-0f7e-5456-b54f-e95f7bf44af4
STIX ID: report--9c3c64f0-0f7e-5456-b54f-e95f7bf44af4
Feed Name: WatchGuard Secplicity Blog
This disclosure documents insecure design and implementation in the Ouvis C2 HD IP camera: an exposed Telnet service with a hard-coded root password hash (shared across multiple OEM models) and an authenticated CGI-based remote code execution via unsanitized FTP configuration. The researcher achieved root access through UART, demonstrated command execution, reported the issues to the vendor with no response, and publicly released the findings after the disclosure deadline.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
