POLICY-OTHER --
POLICY-OTHER Reolink multiple devices default credentials login attempt
This rule looks for login requests to Reolink web servers that attempt to authenticate using the default admin credentials, "admin:123456".
This rule fires on attempts to login to Reolink devices using the default admin credentials.
Attacks/Scans seen in the wild
Known false positives, with the described conditions
This rule will fire on any attempts to login to Reolink devices with the credentials "admin:123456".
Cisco Talos Intelligence Group
Rule Categories::Server::Web Applications
Rule Categories::Policy::Other
MITRE::ATT&CK Framework::Enterprise::Privilege Escalation::Valid Accounts::Default Accounts
N/A
Not Applicable
CVE-2019-11001 |
Loading description
|