CVE-2018-18767
20.12.2018, 23:29
An issue was discovered in D-Link 'myDlink Baby App' version 2.04.06. Whenever actions are performed from the app (e.g., change camera settings or play lullabies), it communicates directly with the Wi-Fi camera (D-Link 825L firmware 1.08) with the credentials (username and password) in base64 cleartext. An attacker could conduct an MitM attack on the local network and very easily obtain these credentials.Enginsight
| Vendor | Product | Version |
|---|---|---|
| dlink | mydlink_baby_camera_monitor | 2.04.06 |
| d-link | dcs-825l_firmware | 1.08 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration