CVE-2024-5634
Longse model LBH30FE200W cameras, as well as products based on this device, make use of telnet passwords which follow a specific pattern. Once the pattern is known, brute-forcing the password becomes relatively easy. Additionally, every camera with the same firmware version shares the same password.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.20%
- CWE
- CWE-1391
- Published
- 2024-07-09
- Last modified
- 2026-03-13
Affected products
- Longse Technology LBH30FE200W
- Zamel ZMB-01/C
Weakness type
Related vulnerabilities
- CVE-2026-79679 — Use of Weak Credentials
- CVE-2026-66409 — DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot...
- CVE-2026-66408 — The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords....
- CVE-2026-49852 — joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
- CVE-2026-45363 — `jwt` (Ruby gem) - empty-key HMAC bypass
- CVE-2026-57473 — A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to...
- CVE-2026-47325 — Weak password policy in ProjectsAndPrograms school-management-system
- CVE-2026-4377 — Use of Weak Credentials in D-Link DWR-X1820 router