Barni's vulnerability profile centers on network-accessible IP camera hardware and its firmware, where the durable signal reflects authentication and information-disclosure weaknesses including hard-coded credentials, exposure of sensitive data, and unrestricted file uploads. Treat this as a focused embedded-device vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Barni over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-8387CRITICAL MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component. | May 8, 2019 | 9.8 | 73 | NO | YES |
CVE-2018-5726CRITICAL MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to obtain sensitive information via a crafted HTTP request, as demonstrated by the username, password, and configuration | Jan 16, 2018 | 9.8 | 51 | NO | YES |
CVE-2018-5724CRITICAL MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore.cgi. | Jan 16, 2018 | 9.8 | 49 | NO | YES |
CVE-2018-5723CRITICAL MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account. | Jan 16, 2018 | 9.8 | 46 | NO | YES |
CVE-2018-5725HIGH MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of the web server. | Jan 16, 2018 | 7.5 | 36 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Barni.
Media articles that mention a CVE ID that affects a product developed by Barni — matched by CVE ID, not by vendor name.