The edges of Surveilance System and its supply chain
Chanin Kim, Myounghun Pak
DEF CON 32 Main Stage · Day 1 · Main Stage
Overview
This talk, "What's Being Watched: Exploiting the Surveillance System and its Supply Chain," presented by Chanin Kim and Myounghun Pak, delves into critical security vulnerabilities within Network Video Recorders (NVRs) and the broader surveillance system ecosystem. The speakers embarked on a "four-month journey" of vulnerability research, culminating in the discovery of issues that led to a $30,000 bounty. Their research highlights the pervasive nature of surveillance devices in modern life, from smart cities to access control systems, a market currently valued at $4.1 billion. Despite their growing importance, NVRs have received comparatively less security scrutiny than other components like CCTV or IP cameras.

Key moments
- 0:50 Talk introduction: $30,000 bounty and Defcon journey
- 1:00 Demonstrating real-world surveillance system exploitation
- 1:45 Importance of securing surveillance devices and market size
- 2:30 Why Network Video Recorders (NVRs) are targeted
- 3:55 Selected vendors and Mirai botnet vulnerability context
- 4:20 Firmware extraction methodology and bypass challenges
- 6:20 Discovery of hidden OEM surveillance device supply chain
What's Being Watched: Exploiting the Surveillance System and its Supply Chain
Speakers: Chanin Kim, Offensive Researcher, SW; Myounghun Pak, Student, Offensive Research
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=v6VMEeUcqzo
Overview
This talk, "What's Being Watched: Exploiting the Surveillance System and its Supply Chain," presented by Chanin Kim and Myounghun Pak, delves into critical security vulnerabilities within Network Video Recorders (NVRs) and the broader surveillance system ecosystem. The speakers embarked on a "four-month journey" of vulnerability research, culminating in the discovery of issues that led to a $30,000 bounty. Their research highlights the pervasive nature of surveillance devices in modern life, from smart cities to access control systems, a market currently valued at $4.1 billion. Despite their growing importance, NVRs have received comparatively less security scrutiny than other components like CCTV or IP cameras.
The core motivation behind this research stems from the significant internet exposure of NVR devices, with over 30,000 found publicly accessible via Shodan. Previous incidents, such as the 2021 Mirai botnet leveraging Remote Code Execution (RCE) vulnerabilities in similar devices for data attacks, underscore the severe real-world impact of insecure surveillance infrastructure. Kim and Pak's work not only uncovers vulnerabilities in leading NVR vendors but also critically examines the Original Equipment Manufacturer (OEM) and Original Design Manufacturer (ODM) supply chain model, revealing how a single vulnerability can propagate across numerous rebranded devices, creating a widespread security risk without users' awareness.
The presentation aims to demonstrate the feasibility of real-world exploitation scenarios, mirroring sophisticated attacks observed from groups like "Iranian hackers," by showcasing how adversaries could gain control over these systems. By focusing on NVRs, which act as the "brain" of surveillance networks, the research emphasizes the profound implications of compromising these devices for privacy, physical security, and critical infrastructure. The findings serve as a stark reminder for both manufacturers and end-users about the urgent need to enhance the security posture of the global surveillance apparatus.
Background
▶ Watch: Talk introduction: $30,000 bounty and Defcon journey (0:50)
Surveillance systems, once confined to specific security applications, have permeated nearly every aspect of modern life. The COVID-19 pandemic significantly accelerated the demand for these devices, expanding their use across diverse sectors including retail stores, smart cities initiatives, and advanced access control systems. This proliferation has positioned surveillance technology as an indispensable component of infrastructure, managing vast amounts of sensitive visual data. At the heart of many of these systems lies the Network Video Recorder (NVR).
An NVR is a specialized computer system that records, stores, and manages video streams from CCTV (Closed-Circuit Television) and IP cameras. Unlike traditional DVRs (Digital Video Recorders) that process analog signals, NVRs work with digital video data, often over a network, making them highly accessible over the internet for remote monitoring and management. Given their role in aggregating and storing potentially sensitive video feeds, NVRs are a high-value target for malicious actors.
Despite their critical function, the research points out a notable gap in security studies concerning NVRs compared to their camera counterparts. This oversight is particularly concerning given the significant number of these devices exposed online. A Shodan search conducted by the researchers revealed more than 30,000 NVR devices directly accessible from the internet, presenting a vast attack surface. The historical precedent set by the 2021 Mirai botnet, which exploited RCE vulnerabilities in internet-connected devices to launch large-scale distributed denial-of-service (DDoS) attacks, serves as a stark warning of the potential consequences of neglecting NVR security. These critical vulnerabilities, when maliciously exploited, can lead to data theft, system compromise, or even the weaponization of entire surveillance networks.
To address this research gap, the speakers strategically selected target vendors based on market dominance and perceived security posture. Their choices included:
- Hikvision and Dahua: These two Chinese companies hold the largest market share globally in the surveillance system industry.
- A: A leading vendor in the Korean market.
- Synology: Selected specifically because of its reputation for strong security, the researchers aimed to test whether this reputation extended to its surveillance-related packages. This diverse selection allowed for a comprehensive assessment of security practices across different market segments and security philosophies.
Key Findings
▶ Watch: Importance of securing surveillance devices and market size (1:45)
The primary findings of this research highlight two critical aspects of surveillance system security: the pervasive nature of vulnerabilities in NVRs from major vendors and the profound impact of the OEM/ODM (Original Equipment Manufacturer/Original Design Manufacturer) supply chain model on disseminating these security flaws. While the provided transcript segment did not detail the specific vulnerabilities discovered (e.g., CVE numbers, exploit types beyond general RCE), it strongly implies that critical flaws were identified across multiple target devices.
The researchers successfully extracted firmware from several NVR devices, a foundational step for vulnerability analysis. This process, often challenging, revealed varying levels of security measures implemented by manufacturers. The ability to extract firmware is a key finding in itself, demonstrating that these "black box" devices can be reverse-engineered and analyzed for weaknesses.
Crucially, the research uncovered the widespread use of the OEM/ODM model within the surveillance industry. Major global suppliers like Hikvision and Dahua produce NVRs that are then re-labeled and sold under different brand names by various vendors, including prominent retailers in the US such as Lorex and Luma. This means that a vulnerability present in the core firmware developed by an OEM supplier can silently exist across dozens, if not hundreds, of different branded products globally. This supply chain dynamic is a critical security finding because it:
- Amplifies Risk: A single flaw in a core OEM product can expose a massive number of end-user devices, often without their knowledge of the true underlying manufacturer.
- Complicates Patching: Identifying all affected downstream brands and ensuring timely patch distribution becomes an arduous, if not impossible, task for consumers and even the OEM vendors themselves.
- Obscures Accountability: The layered nature of the supply chain can make it difficult to determine who is ultimately responsible for addressing security flaws and communicating risks to end-users.
The implication is that users might believe they are purchasing a product from a reputable local brand, unaware that its core components and firmware originate from a potentially less secure or less transparent global supplier. This finding underscores that security in the surveillance ecosystem is not just about individual product vulnerabilities but also about the integrity and transparency of the entire manufacturing and distribution chain. The research effectively demonstrates that the "edges of surveillance systems" extend far beyond the visible device, reaching deep into complex global supply networks.
Technical Deep Dive
▶ Watch: Why Network Video Recorders (NVRs) are targeted (2:30)
The technical core of this research revolved around firmware extraction and the subsequent analysis of the NVRs, particularly focusing on the implications of the OEM/ODM supply chain. The ability to obtain and analyze the device firmware is paramount for identifying underlying vulnerabilities.
The researchers employed a variety of methods for firmware extraction. For three of the four target products (Hikvision, Dahua, and A), direct firmware updates were available, which often contain the complete firmware image. However, for a deeper and more interactive analysis, direct access to the device's operating system was sought. Synology, known for its security focus, provided straightforward shell access, simplifying the process for that particular vendor.
For Hikvision and Dahua, the journey was more challenging. Initial attempts to gain remote shell access were met with proprietary limitations, offering only restricted shell environments that resisted various bypass techniques. This forced the researchers to resort to UART (Universal Asynchronous Receiver-Transmitter) access, a common hardware debugging interface found on many embedded systems. The process involved:
- Identifying UART Ports: Locating the physical UART pins on the NVR's Printed Circuit Board (PCB).
- Connecting Hardware: Using a USB-to-UART converter to establish a serial connection between the NVR and a host PC.
- Interactive Shell: Aiming to achieve an interactive shell environment for direct command input and firmware dumping.
A significant hurdle was encountered when it was discovered that the UART interfaces on three of the devices were modified from standard configurations, preventing direct shell access. This often involves custom bootloaders or stripped-down kernel configurations designed to restrict debug access. The researchers had to find a bypass specific to these modified implementations. For older versions of Hikvision devices, they successfully exploited a quirk involving the set EV; command followed by a semicolon. This specific input sequence, likely a leftover debugging command or a vulnerability in the bootloader's command parsing, allowed them to gain the necessary access to interact with the device's shell and extract firmware. This highlights the importance of thorough hardware-level analysis and the persistence required in embedded system security research.
Beyond firmware extraction, a key technical revelation pertains to the OEM/ODM supply chain model. As mentioned, Hikvision and Dahua are massive OEM suppliers. This means they manufacture devices (or design them, in the case of ODM) that are then rebranded and sold by other companies. The speakers provided examples like Lorex and Luma, which are US retailers selling devices that are essentially rebranded Hikvision or Dahua NVRs. This "relabeling" process means that the underlying hardware and, critically, the firmware are largely identical across different brands.
The technical implication of this model is profound: a vulnerability discovered in the firmware of a Hikvision NVR, for instance, is highly likely to exist in a Lorex NVR that uses the same OEM firmware. This creates a vast attack surface where a single exploit can potentially compromise a multitude of devices sold under different names globally. From a technical analysis perspective, this means that vulnerabilities found in one OEM-supplied device can be generalized and tested against other rebranded products, significantly expanding the scope of a single discovery. This supply chain aspect transforms isolated product vulnerabilities into systemic industry-wide risks, making patching and mitigation efforts exponentially more complex.
It is important to note that while the speakers indicated they would discuss "the various vulnerabilities that could be exploited in the world and their scenarios," the detailed technical descriptions of these specific vulnerabilities (e.g., specific code flaws, exploit techniques beyond the firmware extraction bypass) were not included in the provided transcript segment.
Demo / Proof of Concept
▶ Watch: Firmware extraction methodology and bypass challenges (4:20)
The speakers introduced their talk with a compelling video demonstration, serving as a proof of concept (PoC) for the real-world implications of their research. The video aimed to visually represent the "final goal" of their work – the successful exploitation of surveillance systems, echoing the capabilities of sophisticated threat actors.
The demonstration depicted a scenario reminiscent of a "hacker from a movie," illustrating how an attacker could gain unauthorized control over a surveillance system. This visual proof was inspired by actual incidents, specifically mentioning attacks perpetrated by "Iranian hackers" who have previously compromised such systems. While the exact technical steps of the PoC were not detailed in the transcript, the objective was clear: to show that the vulnerabilities discovered in NVRs could lead to a complete takeover of the surveillance infrastructure.
This type of demonstration typically involves:
- Initial Access: Exploiting a vulnerability (e.g., RCE, authentication bypass) to gain a foothold on the NVR.
- System Control: Executing commands on the device, potentially manipulating video feeds, disabling recording, or exfiltrating data.
- Visual Impact: Displaying the compromised state, such as showing manipulated video on a monitor or demonstrating an attacker's message appearing on the NVR's interface.
The PoC served to underscore the critical nature of the vulnerabilities and the tangible threat they pose. By successfully replicating the outcomes of real-world attacks, the researchers validated the severity of their findings and the urgent need for improved security in the surveillance sector. The visual nature of the demo made the abstract concept of NVR vulnerabilities immediately relatable and impactful, highlighting how compromised NVRs can be used for espionage, sabotage, or even as launchpads for further network intrusions.
Defensive Implications
▶ Watch: Discovery of hidden OEM surveillance device supply chain (6:20)
The findings presented in this research carry significant defensive implications for organizations and individuals deploying surveillance systems. Given the critical role of NVRs and the widespread impact of the OEM/ODM supply chain, a multi-faceted approach is necessary to mitigate risks.
- Prioritize Patching and Updates: The most immediate and crucial defense is to ensure that NVRs and associated surveillance devices are kept up-to-date with the latest firmware patches. Manufacturers frequently release security updates to address discovered vulnerabilities. Organizations must establish robust patch management processes to apply these updates promptly. This is especially critical for devices exposed to the internet.
- Network Segmentation: NVRs and IP cameras should be isolated on dedicated network segments, separate from critical business or personal networks. Utilizing VLANs or physical separation can prevent attackers who compromise a surveillance device from easily pivoting to other sensitive systems within the network. If remote access is necessary, it should be strictly controlled, ideally through a VPN with multi-factor authentication.
- Awareness of OEM/ODM Risks: Defenders must be aware that devices from different brands may share common underlying firmware due to the OEM/ODM model. This means a vulnerability in one brand could affect another. Organizations should research the actual manufacturer of their devices, not just the brand name, and monitor security advisories from both the brand vendor and the underlying OEM supplier (e.g., Hikvision, Dahua).
- Strong Authentication and Access Control: Default credentials must be changed immediately upon installation. Strong, unique passwords should be enforced for all NVR accounts, and multi-factor authentication (MFA) should be enabled wherever possible. Access to NVR interfaces, both physical and remote, should be restricted to authorized personnel only.
- Disable Unnecessary Services: Many NVRs come with a range of services enabled by default that may not be required for typical operation. Disabling unnecessary ports, protocols, and features reduces the attack surface. For example, if remote access is not needed, ensure it is disabled.
- Regular Security Audits and Penetration Testing: Proactive security assessments, including vulnerability scanning and penetration testing of surveillance infrastructure, can help identify weaknesses before attackers do. This should encompass both network-facing and local interfaces of NVRs and cameras.
- Environmental Monitoring and Logging: Implement robust logging on NVRs and network devices to detect unusual activity, such as failed login attempts, unauthorized access, or unexpected network traffic. Integrate these logs into a centralized security information and event management (SIEM) system for effective monitoring and alerting.
- Physical Security: Do not overlook the physical security of NVRs. They should be housed in secure locations with restricted access to prevent tampering, physical firmware extraction attempts (like UART access), or theft.
By adopting these defensive strategies, organizations can significantly enhance the security posture of their surveillance systems, protecting against the types of critical vulnerabilities and supply chain risks highlighted by this research.
Key Takeaways
- NVRs are Critical and Under-Secured: Network Video Recorders (NVRs) are the "brain" of surveillance systems, crucial for security and data storage, yet they receive less security research attention than other components, making them high-value targets.
- Widespread Internet Exposure: Over 30,000 NVR devices are directly exposed to the internet via Shodan, presenting a massive and easily discoverable attack surface for malicious actors.
- OEM/ODM Model Amplifies Risk: The widespread use of the Original Equipment Manufacturer/Original Design Manufacturer (OEM/ODM) model means that a single vulnerability in core firmware from suppliers like Hikvision or Dahua can affect numerous rebranded products (e.g., Lorex, Luma), creating systemic, hard-to-patch risks across the industry.
- Firmware Extraction is Key for Analysis: Despite proprietary limitations and modified UART interfaces, researchers demonstrated successful firmware extraction from NVRs, proving that these "black box" devices can be reverse-engineered for vulnerability discovery.
- Real-World Impact is Severe: Critical vulnerabilities in NVRs, including potential Remote Code Execution (RCE), can lead to complete takeover of surveillance systems, as demonstrated by the research and evidenced by historical incidents like the Mirai botnet.
- Defensive Measures are Essential: Organizations must prioritize patching, implement network segmentation, use strong authentication, disable unnecessary services, and conduct regular security audits to protect their surveillance infrastructure from these identified threats.
About the Speaker(s)
Chanin Kim is an offensive researcher currently working at SW. His work focuses on identifying and exploiting vulnerabilities in various systems. In this talk, he shared insights from his extensive vulnerability research journey into surveillance system devices.
Myounghun Pak is a student attending a university in Korea, where he is actively involved in offensive security research. He collaborated with Chanin Kim on this project, contributing to the detailed investigation of surveillance system vulnerabilities and their supply chain implications.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
This research meticulously dissects the security posture of Network Video Recorders (NVRs), a largely overlooked yet critical component of global surveillance infrastructure. The team's extensive, hands-on investigation yielded significant vulnerabilities, including clever hardware-level bypasses for firmware extraction. Crucially, the talk exposes the profound, amplifying effect of the OEM/ODM supply chain model, demonstrating how a single flaw can silently propagate across countless rebranded devices. This work provides invaluable, actionable intelligence on a systemic risk that demands immediate attention from both manufacturers and defenders.
Heather Calloway (CISO) — STRONG ACCEPT
This talk provides a clear, unsentimental look at a pervasive and often neglected area of institutional risk: networked video recorders (NVRs) and their deeply flawed supply chain. By revealing how a single vulnerability can propagate across countless rebranded devices, the speakers expose a critical governance gap. The research translates technical findings into actionable insights for defenders and leaders, making a strong case for immediate, focused attention on these high-value, under-secured assets. It's a valuable contribution for any organization reliant on physical security infrastructure.