DVR Firmware for multiple vendors contains hard-coded creds
概要
CWE-259: Use of Hard-coded Password - CVE-2015-8286
According to the reporter, DVR devices based on the Zhuhai RaySharp firmware contain a hard-coded root password. Remote attackers with knowledge of the password may gain root access to the device.
Furthermore, it was previously reported publicly that many of these devices enable remote access via telnet or port 9000 by default.
The CERT/CC has not been able to confirm this information directly with Zhuhai RaySharp. The Vendor List below provides more information on each manufacturer that was reported to be vulnerable.
The reporter, Risk Based Security, has provided security advisory RBS-2016-001 with more information
Created: 2026-02-23
Indicators
Indicatorsは見つかっていない。
類似Pulses
このPulseに関連する脅威アクター (事実ベース)
Score: 14.27
Matched TTPs:
- T1110.001 - Password Guessing
- T1190 - Exploit Public-Facing Application
- T1669 - Wi-Fi Networks
- T1211 - Exploitation for Defense Evasion
MITREへのリンク →
Score: 5.60
Matched TTPs:
- T1110.001 - Password Guessing
- T1190 - Exploit Public-Facing Application
MITREへのリンク →
Score: 3.12
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 5.95
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1021.001 - Remote Desktop Protocol
- T1680 - Local Storage Discovery
MITREへのリンク →
Score: 5.95
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1021.001 - Remote Desktop Protocol
- T1680 - Local Storage Discovery
MITREへのリンク →
Score: 5.09
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1078.001 - Default Accounts
MITREへのリンク →
Score: 6.74
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1078.001 - Default Accounts
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 6.74
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1078.001 - Default Accounts
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 5.86
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1573.002 - Asymmetric Cryptography
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 3.12
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 3.12
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 3.12
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 3.12
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 4.30
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1680 - Local Storage Discovery
MITREへのリンク →
Score: 3.12
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 3.12
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 3.12
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 5.09
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1078.001 - Default Accounts
MITREへのリンク →
Score: 3.12
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 3.12
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 3.12
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 3.12
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 3.12
Matched TTPs:
- T1190 - Exploit Public-Facing Application
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 6.88
Matched TTPs:
- T1573.002 - Asymmetric Cryptography
- T1211 - Exploitation for Defense Evasion
MITREへのリンク →
Score: 5.58
Matched TTPs:
- T1573.002 - Asymmetric Cryptography
- T1680 - Local Storage Discovery
MITREへのリンク →
Score: 4.39
Matched TTPs:
- T1573.002 - Asymmetric Cryptography
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 4.39
Matched TTPs:
- T1573.002 - Asymmetric Cryptography
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 4.39
Matched TTPs:
- T1573.002 - Asymmetric Cryptography
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 4.39
Matched TTPs:
- T1573.002 - Asymmetric Cryptography
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 6.19
Matched TTPs:
- T1538 - Cloud Service Dashboard
- T1021.001 - Remote Desktop Protocol
MITREへのリンク →
Score: 4.48
Matched TTPs:
- T1021.001 - Remote Desktop Protocol
- T1680 - Local Storage Discovery
MITREへのリンク →
Score: 4.48
Matched TTPs:
- T1021.001 - Remote Desktop Protocol
- T1680 - Local Storage Discovery
MITREへのリンク →
Score: 4.48
Matched TTPs:
- T1021.001 - Remote Desktop Protocol
- T1680 - Local Storage Discovery
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.78
Matched TTPs:
- T1669 - Wi-Fi Networks
- T1190 - Exploit Public-Facing Application
- T1211 - Exploitation for Defense Evasion
- T1110.001 - Password Guessing
MITREへのリンク →
Related CVEs
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る