VYPR
Unrated severityNVD Advisory· Published Nov 17, 2020· Updated Aug 4, 2024

CVE-2020-27557

CVE-2020-27557

Description

Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to gain access to the video streaming username and password via SQLite files containing plain text credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

BASETech GE-131 IP camera firmware 20180921 stores video-streaming credentials in plain text in an unprotected SQLite file, enabling local attackers to read them.

Vulnerability

BASETech GE-131 BT-1837836 IP camera firmware version 20180921 contains an unprotected storage of credentials vulnerability [1]. The camera stores the username and password for video streaming access in plain text within SQLite database files [1]. These files are accessible to any user with local access to the camera's file system [1].

Exploitation

An attacker must have local access to the camera — for example, via the same local network if the camera's storage is exposed over a network share, or by physically accessing the device's storage (e.g., removing an SD card if one is present, or connecting via debug interfaces) [1]. Once local access is achieved, the attacker can read the SQLite files containing the credentials directly using any SQLite viewer [1]. No authentication or user interaction beyond gaining local access is required [1].

Impact

Successful exploitation allows the attacker to retrieve the plain-text username and password used for the video streaming service [1]. With these credentials, the attacker can access the camera's live video stream, leading to unauthorized disclosure of video footage [1]. The attacker gains no further system privileges beyond the ability to view the video stream [1].

Mitigation

As of the reference publication (November 2020), no firmware update or patch has been released by BASETech for this camera, and the device appears to be end-of-life with no vendor support [1]. The only effective mitigation is to replace the camera with a device that receives security updates, or to isolate it on a separate network segment that prevents local access by untrusted users [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.