A vulnerability in Hipcam Cameras RealServer version 1.0 allows remote attackers to trigger a denial of service condition by sending a crafted script to the client_port parameter. The vulnerability is due to insufficient input validation on the client_port parameter, which can be exploited to disrupt the normal operation of the service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a minimal proof-of-concept for CVE-2023-50685 affecting Hipcam RealServer V1.0. It contains two files: a README describing the vulnerability, impact, and usage, and a single Python script (poc.py) that implements the exploit logic. The script uses Python's socket module to open a TCP connection to a user-supplied IP and port, constructs an RTSP SETUP request for the path /11/trackID=1, and injects an invalid Transport header client_port value as a single random integer instead of the expected port-range format. No response parsing, verification, brute force, authentication handling, or persistence is implemented. The exploit capability is limited to network-based denial of service / stream disruption against exposed RTSP services; the README claims the stream goes offline for about 45 seconds after successful triggering. The code is straightforward and operational as a basic POC, but it does not include a customizable post-exploitation payload or advanced targeting logic.
This repository contains a proof-of-concept exploit (poc.py) and a detailed README for CVE-2023-50685, a format validation vulnerability in the Hipcam RealServer/V1.0 RTSP service. The exploit targets the 'client_port' parameter in the RTSP SETUP request, sending a malformed value to disrupt the RTSP stream. The Python script (poc.py) takes a target IP and port as arguments, crafts the malicious RTSP request, and sends it to the target device over TCP. If successful, the RTSP stream is disrupted for about 45 seconds, resulting in a temporary denial of service. The README provides background, usage instructions, and context about the vulnerability and its impact. No hardcoded IPs or credentials are present; the script is generic and requires the user to specify the target. The repository is structured simply, with one exploit script and one documentation file.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.