Blurams Flare Camera Insecure Authentication in Startup Script Allows Root Command Execution

Vulnerability

A vulnerability exists in the safe_exec.sh startup script of Blurams Flare Camera, specifically in versions through 24.1114.151.929. The issue arises from an insecure authentication mechanism that enables an attacker with physical access to the device to execute arbitrary commands with root privileges. This exploitation is possible if the file /opt/images/public_key.der is absent from the file system. The vulnerability can be triggered by placing a maliciously crafted auth.ini file on the device's SD card.

Impact

Exploitation of this vulnerability allows for arbitrary command execution with root privileges on the affected device.

Reproduction

To reproduce this vulnerability, physically access the Blurams Flare Camera running a vulnerable version. Ensure that the file /opt/images/public_key.der is not present on the device. Then, create a malicious auth.ini file and place it on the device's SD card. When the camera is started, the unsafe authentication mechanism will be exploited, allowing arbitrary commands to be executed with root privileges.

Added: Jan 14, 2026, 6:28 PM
Updated: Jan 14, 2026, 8:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
1.8
remediation
0.0
relevance
2.1
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.