HomeSecurityWyze Cam v3: RCE vulnerability in the camera, update immediately

Wyze Cam v3: RCE vulnerability in the camera, update immediately

A security researcher has published a PoC script for an RCE exploit in devices , which opens a reverse shell and allows the capture of vulnerable devices.

See also: VMware: Publicly exploiting RCE flaw in vRealize
Wyze Cam v3

The Wyze Cam v3 security camera is a popular and affordable solution for indoor and outdoor use, providing support for color night vision, SD card storage, cloud connectivity for smartphone control , IP65-certified weather resistance, and more.

Security researcher Peter Geissler (aka bl4sty) recently discovered two vulnerabilities in the latest firmware of the Wyze Cam v3 camera that can be exploited for remote code execution on vulnerable devices.

The first issue is an arbitrary DTLS (Datagram Transport Layer Security) authentication bypass in the 'iCamera' daemon, allowing attackers to use arbitrary PSKs (Pre-Shared Keys) during the TLS handshake process to bypass security measures.

The second flaw occurs after the DTLS authenticated session is established, when the client sends a JSON object. The iCamera code that parses this object can be exploited due to mishandling of a specific array, leading to a stack buffer overflow where data is written to unintended parts of memory.

See also: SolarWinds: Serious RCE vulnerabilities discovered

Attackers can exploit the second vulnerability to replace stack memory and, given the lack of security features such as stack canaries and independent execution in the iCamera code, execute their own code on the camera.

The PoC published by Geissler on GitHub combines these two flaws to give attackers an intrusive Linux root shell, turning vulnerable Wyze v3 cameras into permanent backdoors and allowing attackers to target other devices on the network.

RCE

The software versions affected by this vulnerability are 4.36.10.4054, 4.36.11.4679 and 4.36.11.5859.

Wyze released a firmware update with version 4.36.11.7071, which addresses the identified issues, on October 22, 2023. Users to install the security update as soon as possible.

See also: GNOME Linux: Exposed to RCE attacks via file downloads

Users can take a few steps to protect their Wyze Cam v3 from RCE exploits. First and foremost, it's important to keep it up to date with the latest software updates that Wyze provides for device . These updates typically include security fixes that can prevent RCE exploits.

Additionally, users must maintain strong passwords for their camera and change them regularly. A strong password should include a combination of uppercase and lowercase letters, numbers, and special characters. This can make exploiting an RCE vulnerability more difficult.

Additionally, users should disable remote access on the Wyze Cam v3 unless they truly need it. Disabling this feature reduces the risk of exploitation by malicious users.

Finally, users can choose to use an additional layer of security, such as a virtual private network (VPN), to protect their camera from external threats. A VPN encrypts the connection between the device and the network, adding an extra layer of security.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS