First published: Sun Oct 16 2011(Updated: )
/etc/rc.d/rc.local on the D-Link DCS-2121 camera with firmware 1.04 configures a hardcoded password of admin for the root account, which makes it easier for remote attackers to obtain shell access by leveraging a running telnetd server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
dlink DCS-2121 firmware | =1.04 | |
dlink DCS-2121 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4965 is considered a high severity vulnerability due to the exposure of a hardcoded password that allows remote attackers to gain shell access.
To fix CVE-2010-4965, upgrade the firmware on the D-Link DCS-2121 camera to a version that does not contain the hardcoded password.
The consequences of CVE-2010-4965 include potential unauthorized access to the camera's system which could lead to data breaches or the compromise of the device.
CVE-2010-4965 is still a risk if the affected firmware version 1.04 remains in use and has not been updated subsequently.
CVE-2010-4965 specifically affects the D-Link DCS-2121 camera running firmware version 1.04.