Security News > 2020 > March > Hackers Actively Exploit 0-Day in CCTV Camera Hardware
Multiple zero-day vulnerabilities were actively being exploited in CCTV security cameras manufactured by Taiwan-based LILIN, researchers found.
The company, an IP video solution provider, was being targeted by hackers hijacking the company's DVR hardware.
Once commandeered, hackers then planted malware on devices to run botnets Chalubo, FBot and Moobot.
As for the LILIN DVR vulnerability specifics, one is tied to the DRV's NTPDate computer program.
Similar injection vulnerabilities exist within the software's FTP settings that eventually allow remote access to the "/dvr/cmd" interface through hard-coded account passwords.
News URL
Related news
- Hackers Exploit Webview2 to Deploy CoinLurker Malware and Evade Security Detection (source)
- Hackers exploit DoS flaw to disable Palo Alto Networks firewalls (source)
- Hackers exploit Four-Faith router flaw to open reverse shells (source)
- Hackers exploit KerioControl firewall flaw to steal admin CSRF tokens (source)
- Mitel 0-day, 5-year-old Oracle RCE bug under active exploit (source)
- Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners (source)
- Hackers exploit critical Aviatrix Controller RCE flaw in attacks (source)
- Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnet (source)
- Hackers exploit 16 zero-days on first day of Pwn2Own Automotive 2025 (source)
- Hackers exploit critical unpatched flaw in Zyxel CPE devices (source)