Peekaboo Zero-Day Vulnerability Permits Hacking Of Surveillance Cameras

Share It On:

Security cameras of IoT that represents various vendors invite opportunities for flaws. Recently, researchers have discerned a similar vulnerability that lets the hacking of surveillance cameras. By employing this “Peekaboo zero-day vulnerability” in the NUUO software, an attacker could remotely perform arbitrary commands.

Vulnerabilities In NUUO Software Allows Hacking Surveillance Cameras

 A study that was made in cybersecurity firm Tenable have discovered two different vulnerabilities in video management software NUUO that allow hacking of surveillance cameras. As mentioned on its official website, NUUO enjoys over 100,000 installations worldwide. Hence, one can envisage the enormous impact of the vulnerabilities reported by Tenable.

As the per the report, researchers have found two different flaws in the NUUO security system for which they have provided a POC as well in their report. These vulnerabilities mainly affect the NVRMini2 – network-attached storage and video recording tool. One of these vulnerabilities, “The Mystery of the Backdoor” (CVE-2018-1150) is a Medium severity rated fault developed due to “leftover debug code.” Explaining this vulnerability, the researchers state,

“If a file named /tmp/Moses exists, the backdoor is enabled. It permits the listing of all user accounts on a system and allows someone to change any account’s password. This would, for example, permit an attacker to view the camera feeds, view CCTV recordings, or remove a camera from the system entirely.” [Latest hacking news]

An attacker needs to create file “/tmp/Moses” which may require exploiting another vulnerability to develop this vulnerability,

The other susceptibility, which is significantly important, is a zero-day vulnerability named “Peekaboo.” This vulnerability (CVE-2018-1149) carries a Temporal Score of 8.6 with a “Critical” severity rating. It is an “unauthenticated stack buffer overflow” vulnerability that permits remote code execution by the attacker. Jacob Baines, Tenable’s Senior Research Engineer, has developed the proof-of-concept demonstrating this error.

About the Peekaboo zero-day vulnerability, the researchers explain,

“The NVRMini2 uses an open-source web server that holds up some executable binaries via the common gateway interface (CGI) protocol. One of the CGI binaries that can be applied on the NVRMini2 is ‘cgi_system,’ and it can be accessed via http://x.x.x.x/cgi-bin/cgi_system. This binary handles a variety of commands and actions that necessitate the user be authenticated.

During authentication, the cookie parameter’s session ID size isn’t checked, which allows for a stack buffer overflow in the sprintf function. This vulnerability allows for remote code execution with “root” or administrator privileges.” [Latest hacking news]


Share It On:

Recent Posts

NRB’s NPR 6.8 Billion Investment: Strengthening Nepal’s Financial Future and Banking Stability

NRB’s NPR 6.8 Billion Investment: Strengthening Nepal’s Financial Future and

Share It On:23rd November 2024, Kathmandu Nepal’s Central Bank, Nepal Rastra Bank (NRB), has announced a significant investment of NPR

Nepal’s ADB Prioritizes Farmers’ Welfare for Economic Growth and Agricultural Development

Nepal’s ADB Prioritizes Farmers’ Welfare for Economic Growth and Agricultural

Share It On: 23rd November 2024, Kathmandu The Agricultural Development Bank (ADB) is recognized as a vital institution for Nepal’s

Ridi Power’s 23rd AGM Concludes: Key Decisions, Investments, and Future Outlook

Ridi Power’s 23rd AGM Concludes: Key Decisions, Investments, and Future

Share It On: 23rd November 2024, Kathmandu Ridi Power Company Limited wrapped up its annual shareholder meeting, the 23rd Annual

Nepal Oman Financial Ties Strengthen: Omani Rial Now Legal Tender In Nepal

Nepal Oman Financial Ties Strengthen: Omani Rial Now Legal Tender

Share It On: 22nd November 2024, Kathmandu A significant step has been taken towards strengthening financial ties between Nepal and

Liberty Energy Rights Shares Offering: Eligibility, Application Process, and Future Plans

Liberty Energy Rights Shares Offering: Eligibility, Application Process, and Future

Share It On:22nd November 2024, Kathmandu Liberty Energy Company Limited is gearing up to issue rights shares starting December 1,

Asha Laghubitta’s 8th AGM 2024: Key Decisions and Future Plans

Asha Laghubitta’s 8th AGM 2024: Key Decisions and Future Plans

Share It On:22nd November 2024, Kathmandu Asha Laghubitta Bittiya Sanstha is holding its 8th Annual General Meeting (AGM) today, November