FNKvision Y215 CCTV Camera Information Disclosure Vulnerability

Vulnerability

A vulnerability exists in the FNKvision Y215 CCTV camera running version 10.194.120.40, where the Wi-Fi SSID and password are stored in plaintext in multiple locations, including /tmp/wpa_supplicant.conf and system/param/network.ini. This information can be accessed through a firmware dump or via serial/UART access, exposing sensitive network credentials. The vulnerability has been classified as problematic, with a CVSSv3 score of 1.5.

Impact

Exploitation of this vulnerability leads to unauthorized access to sensitive Wi-Fi credentials, which could be used to intercept or manipulate network traffic.

Reproduction

The vulnerability can be reproduced by accessing the camera's firmware through a CH341A programmer, which can then be analyzed with Ghidra. The Wi-Fi credentials can be extracted from the firmware dump using a grep search. Alternatively, the credentials can be accessed directly from the camera's filesystem via the serial console.

Added: Aug 24, 2025, 8:18 AM
Updated: Aug 24, 2025, 8:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
0.0
relevance
0.4
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.