Attack Vector

"To perform the attack, a hacker would first run an exploit for CVE-2018-10661, an authorization bypass that allows the attacker to access /bin/ssid, which runs as root, via unauthenticated HTTP requests."

Being a CCTV installer (Thankfully not one that uses Axis, although I believe their kit is far from the low-level stuff lika Dahua and whatnot) - I can't envisage one of our cameras' interfaces ever being exposed to the internet for someone to perform this attack. I'm *NOT* saying this means it's acceptable to have such a vulnerability, but the chances of a camera sitting on an open port-80 even without any known exploits is asking for serious trouble!

