Telnet Credential Vulnerability in Smartwares Cameras
CVE-2024-13893

7.5HIGH

Key Information:

Vendor

Smartwares

Vendor
CVE Published:
6 March 2025

What is CVE-2024-13893?

Smartwares cameras, including models CIP-37210AT and C724IP, exhibit a vulnerability where shared telnet service credentials can be compromised. This occurs in firmware versions up to 3.3.0, with the password hashes retrievable via physical access to the SPI connected memory. The telnet service can be activated by creating a specially named folder on the inserted SD card. The absence of a response from the vendor regarding reports raises concerns about the patching status and the potential for other devices with similar firmware to harbor the same vulnerability. Users are advised to remain vigilant as newer firmware versions may also be at risk.

Affected Version(s)

C724IP 0 <= 3.3.0

CIP-37210AT 0 <= 3.3.0

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michał Majchrowicz (Afine Team)
Marcin Wyczechowski (Afine Team)
.
CVE-2024-13893 : Telnet Credential Vulnerability in Smartwares Cameras