Annke N48PBB NVR vulnerability

watchful_ip

Pulling my weight
Nov 24, 2019
259
242
london
If you have one of these on the Internet you might want to update. And reconsider having any IoT exposed to the internet in the first place :)

 
I thought the Annke N48PBB was one of their Hikvision oem NVRs.

Oh, there’s a picture of the mainboard in the Nozomi article:
1630314564193.jpeg
It says on it DS-80325_P.
 
Last edited:
I looked at the firmware - it is Hikvision OEM.

But the vulnerable code looks to have been added by Annke themselves, as the Hikvision firmware doesn't seem to have it (though I didn't check everything so might have missed it, but I am sure it would have been noted).

The fast response may have been because the fixed firmware has a build date in April - before the vulnerability was reported.
 
  • Like
Reactions: alastairstevenson