黑客组织stegan0gram通过DDoSecrets发布了Flock自动车牌识别摄像头的固件镜像,揭露该设备存在多项严重安全缺陷。1该摄像头运行的Android 8.1系统发布于2017年,其安全补丁级别停留在2018年6月5日,已落后8年。1同时,设备搭载的Linux 3.18.71内核版本已超过9年未获更新,相比官方停止支持的最后版本落后69个发布版本。1
固件分析发现设备内存在硬编码的API密钥"HaJ3FgupAm8RrDJW3MHgT9X7Ft27eVaD",通过该密钥可获取Auth0客户端ID和密钥,进而获得Flock后端服务器的生产环境访问权限。1此外,摄像头易受CVE-2021-1905(高通Adreno GPU漏洞)和CVE-2018-9568(WrongZone内核漏洞)等已知远程代码执行漏洞影响。1持久化分区(/persist)缺乏加密保护,其中存储的认证凭证以明文形式保存。1
根据GPS日志记录,该摄像头位于美国威斯康星州沃华托萨市N Mayfair Rd,设备序列号为23091220026。1
Hacker group stegan0gram released firmware images of Flock's automatic license plate recognition cameras through DDoSecrets, revealing serious security vulnerabilities that compromise the devices and their backend infrastructure.1 The cameras run Android 8.1, released in 2017, with a security patch level dating to June 5, 2018—over eight years out of date.1 The Linux kernel version 3.18.71 is similarly outdated, falling 69 release versions behind the official end-of-support version and representing more than nine years of accumulated vulnerabilities.1
The firmware contains multiple hardcoded credentials that expose the entire Flock camera network to compromise.1 A hardcoded API key—HaJ3FgupAm8RrDJW3MHgT9X7Ft27eVaD—embedded in the firmware allows attackers to obtain Auth0 client credentials, which in turn grant access to Flock's backend servers.1 Additionally, the persistent storage partition remains unencrypted, storing authentication credentials in plaintext.1 The cameras are vulnerable to at least two known remote code execution flaws: CVE-2021-1905 affecting Qualcomm's Adreno GPU and CVE-2018-9568, a WrongZone kernel vulnerability.1
Analysis of GPS logs traced one of the analyzed cameras to North Mayfair Road in Wauwatosa, Wisconsin, with device serial number 23091220026.1
评论
还没有评论,欢迎留下第一条。