CVE-2021-31793
An issue exists on NightOwl WDB-20-V2 WDB-20-V2_20190314 devices that allows an unauthenticated user to gain access to snapshots and video streams from the doorbell.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.27%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue exists on NightOwl WDB-20-V2 WDB-20-V2_20190314 devices that allows an unauthenticated user to gain access to snapshots and video streams from the doorbell. The binary app offers a web server on port 80 that allows an unauthenticated user to take a snapshot from the doorbell camera via the /snapshot URI.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.27% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- nightowlsp/wdb-20 firmware
- Source
- cve@mitre.org
References
- https://cloud.binary.ninja/embed/f4400a22-c438-403a-bf2a-939ca44a4f6bThird Party Advisory
- https://gist.github.com/tj-oconnor/16a4116050bbcb4717315f519b944f1fThird Party Advisory
- https://cloud.binary.ninja/embed/f4400a22-c438-403a-bf2a-939ca44a4f6bThird Party Advisory
- https://gist.github.com/tj-oconnor/16a4116050bbcb4717315f519b944f1fThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.