« All posts

How a Russian-Speaking Operator Chained Camera and Router CVEs into a Proxy

Explore how an operator exploited camera and router CVEs against Ukraine.

An analysis reveals the offensive workflow of an operator targeting exposed cameras and routers. The custom project, named camview, fingerprints cameras via ONVIF, tests known CVEs, and brute-forces HTTP/RTSP credentials from a comprehensive list, caching successful credentials for future use. Additionally, the operator relayed traffic through a compromised OpenCart admin panel, demonstrating a sophisticated attack methodology.