CVE-2020-27557
Description
Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to gain access to the video streaming username and password via SQLite files containing plain text credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
BASETech GE-131 IP camera firmware 20180921 stores video-streaming credentials in plain text in an unprotected SQLite file, enabling local attackers to read them.
Vulnerability
BASETech GE-131 BT-1837836 IP camera firmware version 20180921 contains an unprotected storage of credentials vulnerability [1]. The camera stores the username and password for video streaming access in plain text within SQLite database files [1]. These files are accessible to any user with local access to the camera's file system [1].
Exploitation
An attacker must have local access to the camera — for example, via the same local network if the camera's storage is exposed over a network share, or by physically accessing the device's storage (e.g., removing an SD card if one is present, or connecting via debug interfaces) [1]. Once local access is achieved, the attacker can read the SQLite files containing the credentials directly using any SQLite viewer [1]. No authentication or user interaction beyond gaining local access is required [1].
Impact
Successful exploitation allows the attacker to retrieve the plain-text username and password used for the video streaming service [1]. With these credentials, the attacker can access the camera's live video stream, leading to unauthorized disclosure of video footage [1]. The attacker gains no further system privileges beyond the ability to view the video stream [1].
Mitigation
As of the reference publication (November 2020), no firmware update or patch has been released by BASETech for this camera, and the device appears to be end-of-life with no vendor support [1]. The only effective mitigation is to replace the camera with a device that receives security updates, or to isolate it on a separate network segment that prevents local access by untrusted users [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- BASETech/GE-131 BT-1837836 firmwaredescription
- Range: = 20180921 firmware
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- infosec.rm-it.de/2020/11/04/basetech-ip-camera-analysis/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.