NONE · 0

CVE-2024-5631

Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a remote control service without using any encryption. T...

Vulnerability Description

Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a remote control service without using any encryption. This enables an on-path attacker to eavesdrop the credentials and subsequently obtain access to the video stream.  The credentials are being sent when a user decides to change his password in router's portal.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-5631?

CVE-2024-5631 is a documented vulnerability. Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a remote control service without using any encryption. T...

How severe is CVE-2024-5631?

CVSS scoring is not yet available for CVE-2024-5631. Check NVD for updates.

Is there a patch for CVE-2024-5631?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.