Dahua RTSP Security Flaw

We have a client that we have installed many Dahua IP cams of various models. The issue we are having is that anyone with access to the camera VLAN can use the standard RTSP string (rtsp://IPADDRESS/axis-cgi/mjpg/video.cgi) to view the camera stream without credentials. Worse yet, doing so changes the Encoding setting on the camera to MJPEG and max frame rate and bit rates. This essentially...

* ******* ******* *** ******* ********* *** ********** **** ** the ******.

****, ** ******** (*** ** *** ** **** ****) **** no ****** **** *** ****, ** ** ** ********* * h.264 ******, *** *****.

** ***** ******* *** ** ******** ****** ** *** ****** using *** ** ****** ******* ** *** ***** ****** ******. One ***** ***** **** * ********* ** ******* ***/**** ***** be * **** ***** ** *****. *******, *** **** ** the ****, *** ** ****** **** *** ***** **** ******. It **** ******* *** ******* ** *** ** ** *** cameras *******.

*** ******* ****** **** ** ** ****** **** **** *** VLAN, ***** ** ***'* **** ******* **, ***, *** ** dept ** ********* ****. **** *** **** *** **** ***** doing ** ** *** ********* **** *** **. ********* *** PC ** *** ******* *** ****** ** *** ****** ****. They *** **** ** ****** ****** *** ****. ** *** inside ***** *** **** ****** **** ********.

*** ***** **, ** **** ******** ********* ** ********. ******* opened ** *** ******* **** **** **** ** *** ** view *** ******* **** ******* **** **** *** **** ** address ** *** ***** ***** *******. **** ******* *** * similar **** ****** ********** **** *** ******* ***** ** *********. When **** ****** ****** **** ****, ** ******* *** * cameras.

****** **** * ******* ** ***** *** ***** ******** ******* this *****?

Login to read this IPVM discussion.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

***. ***** *** * ****** **** * *** **** **** would **** ** *** ***** ****:

  • ***** * *** ******* ******** *** ******* ****** *** ****** settings ** *** ******. ******** ******** ****** ** ********** ** authenticated ***** *** *** ***** ********, *** ******* ********.
  • ** ********* ****** ****** *** ****** ** *** ******, ********** of *** **** ** ******/******.
  • ************** ****** ****** *** **** ******* *****, *** **** ****, ONVIF, ***.

** ***** ** **** **** **** *** **** ***** *** for *************, *** ***'* **** ** ***** ** ******* ** is "***". ********* **** **** * ******* ** ******* **** type ** ******... **** ****.

***, * *** ******* *** ******** ** *** ****** ** mjpeg **** ** ******* *** **** ******. ** * ****** other ******** *** **** **** ******* ** ****. *****'* * post ***** ** *********, *** * ***'* ******* ***** *** a **********.

* ******* ***** *** ***** ** ** ***, *** *** saying **** ******* ** *** ****** ********?

***, ** ** ***** ** ***** *** *** ** *** Dahua ******, *** ** ***** *** ** ** **** **** the ****** ********* ********. * *** *** ******/******** ** ****** or ** ** ***** ******* *** *****.

**, ***** ** ******* ******** ********** ******* *** ***** *** cams ******** *** *** *** ****** *** ******** ******* *.***.*.**.* did ****** *** *** **** *****. * *** ***** *** to ******** *** *** ** **** **** ** **** *** firmware, *** * ***** ****** **** ****** *** ** ** needed.

**, ***** * ******** * *** ******** **** *** *** 3MP ******* *** ** **** ******** *** **** **** **** we *** ****** ****.

****** ** ****** @ *********!

******!

*** ******* ****, ** ******* ***** **** **** ** ********* similar *** ** *** *****, ****** ** ******* ** ***** so * *** ** **** *** *** *** ***** ********.

**** ***** * **** ** ** **** ****** ******** ***** cameras ******* ***********.

**** ****** **** ** ** *** @ *****!

*** ***** ** **** ******* **** *****!