Netwave IP camera devices expose the /proc/kcore pseudo-file, which allows unauthenticated attackers to access a memory dump of the device. This can be exploited to extract sensitive information such as network configuration, including usernames and passwords, without authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Bash exploit script (exploit.sh) targeting Netwave security cameras vulnerable to CVE-2018-17240, a memory leak issue. The exploit works by making HTTP requests to specific endpoints on the camera to retrieve sensitive files: the Wi-Fi configuration file (/etc/RT2870STA.dat), the global configuration via get_status.cgi, and the device's memory via /proc/kcore. The script then parses the memory dump to extract possible credentials (username, password, SSID, PSK) and outputs them for the attacker to use, potentially allowing unauthorized access to the camera's web interface. The repository is simple, with only a README and the exploit script, and is operational as it provides a working method to extract credentials from vulnerable devices.
This repository contains 'Netgrave', a Python-based exploit tool targeting Netwave IP cameras vulnerable to CVE-2018-17240. The vulnerability allows unauthenticated remote attackers to access the /proc/kcore file via HTTP, exposing the device's memory and enabling extraction of sensitive information such as login credentials. The tool can operate against user-specified hosts or automatically discover vulnerable devices using IoT search engines (Censys, Shodan, ZoomEye) via their APIs. The main entry point is 'main.py', which orchestrates host discovery, exploitation, and credential extraction. The core exploitation logic is implemented in 'utils/netwave_device.py', which handles HTTP requests to the camera, memory dump parsing, and credential extraction. The repository is well-structured, with modular code for interacting with different search engines and utility functions. The exploit is operational, providing real credential extraction from live devices, and outputs results to a file ('credentials.txt'). No fake or destructive code is present; the tool is focused on credential extraction for the specified vulnerability.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.