How a Russian-Speaking Operator Chained Camera and Router CVEs into a Proxy
Explore how an operator exploited camera and router CVEs against Ukraine.
An analysis reveals the offensive workflow of an operator targeting exposed cameras and routers. The custom project, named camview, fingerprints cameras via ONVIF, tests known CVEs, and brute-forces HTTP/RTSP credentials from a comprehensive list, caching successful credentials for future use. Additionally, the operator relayed traffic through a compromised OpenCart admin panel, demonstrating a sophisticated attack methodology.