NA

CVE-2021-28732

Published: 08/09/2021 Updated: 07/11/2023

Vulnerability Summary

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-28372. Reason: This candidate is a duplicate of CVE-2021-28372. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2021-28372 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

Vulnerability Trend

Recent Articles

If you haven't updated your ThroughTek DVR since 2018 do so now, warns Mandiant as critical vuln surfaces
The Register • Gareth Corfield • 17 Aug 2021

Get our weekly newsletter Callooh! Kalay! Outdated SDK component poses threat, says intel firm

A critical vulnerability affecting tens of millions of digital video recorders powering baby monitors and CCTV systems across the world has been uncovered by Mandiant, which claims the vuln allows for unauthorised viewing of live camera footage. The vuln exists in Chinese IoT vendor ThroughTek's Kalay communication protocol, the researchers claim, adding that malicious users could exploit the vuln to remotely access victims' DVRs. Exploiting the vuln for real, however, involves carrying out a ma...