한화비전 카메라 펌웨어에 GitHub 관리자 토큰이 포함되어 보안 문제가 발생했다.
한화비전의 카메라 펌웨어에서 웹 관리 UI 파일에 GitHub 관리자 토큰이 하드코딩된 형태로 발견되었습니다. 이 토큰은 수백 개의 저장소에 대한 관리자 권한을 부여하고 있어 보안 위협으로 작용할 수 있습니다. 특히, 펌웨어 내에서 AES 키 복원 과정에 대한 정보도 포함되어 있어, 이 문제는 심각한 보안 결함을 나타냅니다.
A GitHub admin token was found hardcoded in Hanwha Vision camera firmware, posing a security risk.
In the firmware of Hanwha Vision cameras, a GitHub admin token was discovered in the web management UI files. This token grants admin access to hundreds of repositories, potentially leading to significant security vulnerabilities. Additionally, the firmware's AES key recovery process reveals further security weaknesses, indicating a serious flaw.