The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam application through 1.0.5 for Android and the Swisscom Home application up to 10.7.2 for Android), which results in an attacker being able to reuse cookies to bypass authentication and disable the camera.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-09-18T21:00:00
Updated: 2024-08-05T10:17:38.393Z
Reserved: 2018-08-30T00:00:00
Link: CVE-2018-16225
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-09-18T21:29:02.840
Modified: 2024-11-21T03:52:19.257
Link: CVE-2018-16225
Redhat
No data.