Executive brief
A vulnerability in the firmware update process of Qianniao IP security cameras allows an individual with physical access to the device to take complete control. By inserting a specially prepared SD card, an attacker can bypass security measures to gain root-level access, install permanent backdoors, or steal recorded data. This could lead to unauthorized surveillance, loss of privacy, and a total compromise of the camera's security functions.
Technical details
The vulnerability is caused by a lack of integrity and authenticity verification in the boot-time firmware update mechanism (CWE-494, CWE-345). During the boot sequence, the '/etc/init.d/S04app' initialization script checks for the presence of an 'upgrade/' directory on a mounted SD card. If found, it copies a script named 'iu.sh' from the SD card to the local filesystem and executes it with root privileges. An attacker with physical access can place a crafted 'iu.sh' script on an SD card to achieve arbitrary code execution as root, enabling full device compromise and data exfiltration. As of the advisory date, no patch has been confirmed.
Affected products
- Qianniao QN-L23PA0904 IP Security Camera 20250721.1640
Timeline
- 2026-04-02: disclosed: Initial disclosure via MITRE and NVD
- 2026-04-02: advisory: CISA-ADP enrichment and CVSS scoring added