Comment by vorpalhex

2 years ago

Reolink has hardcoded backdoor creds.

https://www.cisa.gov/news-events/ics-advisories/icsa-21-019-...

Correct me if I’m wrong but that appears to apply to the cameras themselves which are not on my network. They plug directly into the NVR (which provides PoE) and are not exposed to the network at large.

  • Why do you assume the NVR is free from hardcoded creds?

    • Because it’s not listed in the list of affected devices. Also if that’s a concern then don’t expose the NVR. Use something like tailscale or a VPN to access it remotely (or don’t access it remotely).

      5 replies →