VYPR
Unrated severityNVD Advisory· Published Sep 1, 2021· Updated Aug 4, 2024

CVE-2021-40380

CVE-2021-40380

Description

An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. cameralist.cgi and setcamera.cgi disclose credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Compro IP70, IP570, IP60, and TN540 cameras expose credentials via unauthenticated access to cameralist.cgi and setcamera.cgi.

Vulnerability

The Compro IP70 (firmware 2.08_7130218), IP570 (firmware 2.08_7130520), IP60, and TN540 network cameras expose sensitive credentials through the cameralist.cgi and setcamera.cgi CGI endpoints. These endpoints are accessible without authentication, allowing any network attacker to retrieve stored usernames and passwords in plaintext [1].

Exploitation

An attacker with network access to the camera can directly request the vulnerable CGI scripts (e.g., http:///cameralist.cgi or http:///setcamera.cgi). No authentication or prior interaction is required. The response contains the camera's administrative credentials in clear text [1].

Impact

Successful exploitation results in full disclosure of the camera's administrative credentials. An attacker can then log into the camera's web interface, change settings, view live video feeds, or pivot to other devices on the network. This compromises the confidentiality and integrity of the camera system [1].

Mitigation

As of the publication date (2021-09-01), no official firmware update or patch has been released by Compro Technology to address this issue. Users are advised to restrict network access to the cameras (e.g., via firewall rules or VLAN segmentation) and monitor for any vendor updates. The affected devices may be end-of-life; contacting the vendor for guidance is recommended [1].

References
  1. Packet Storm

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.