Skip to main content

Guardzilla IoT Surveillance Bypass Vulnerability

Security researchers have disclosed details of a password bypass vulnerability in Guardzilla's All-In-One Video Security System products.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security researchers have disclosed details of a password bypass vulnerability in Guardzilla's All-In-One Video Security System products.


Affected platforms

The following platforms are known to be affected:

Threat details

They claim an unauthenticated remote attacker could exploit this vulnerability to gain access to the video files of all Guardzilla users.

Guardzilla All-In-One devices use a single set of hard-coded Amazon S3 credentials used for storing saved video files. The researchers discovered that these credentials provide full access to the stored files, including those of other users, as well as to Guardzilla's motion detection and recognition modules, and can be easily obtained from any affected device.

For further information:


Remediation steps

Type Step

Users and administrators should visit Guardzilla's support pages for guidance on their affected products.


Last edited: 14 February 2020 2:53 pm