Hourly ·
Security Camera Firmware Shipped with GitHub Admin Token on Its Login Page
A firmware teardown of Hanwha Vision security cameras revealed a GitHub token with admin access to hundreds of repositories — baked into the UI and served to anyone who loaded the camera's login page.
A security researcher tearing down firmware from Hanwha Vision cameras has discovered something startling: a live GitHub token with admin privileges to hundreds of repositories, embedded in the camera's web login page and served to anyone who accessed it.
The researcher — who reverse-engineered the firmware encryption by feeding the camera's upgrade binary to an AI coding agent — found the token duplicated across roughly 30 files in the camera's root filesystem. The token was leaking because the company's Vite build process was capturing the entire CI environment — including GitHub credentials — and baking them into the production JavaScript bundle. Anyone who loaded the camera's admin interface in a browser received the token over the wire.
The token granted administrative access to Hanwha's entire GitHub organization: hundreds of repositories, with full read/write permissions. Even more concerning, the CI environment contained environment variables referencing IP addresses assigned to the U.S. Department of Defense. Hanwha Group's defense subsidiaries — including Hanwha Aerospace and Hanwha Defense USA — manufacture artillery systems, autonomous sentry guns, and armored vehicle subsystems, raising the possibility that the leaked token sat at the intersection of commercial surveillance and military supply chains.
After scraping approximately 500 firmware images across Hanwha's camera lineup and successfully extracting 62% of them, the researcher confirmed the same GitHub token appeared in three camera models. Hanwha responded within 12 hours of disclosure and revoked the token. No evidence of exploitation was found, though the researcher noted that anyone who had ever accessed a vulnerable camera's web interface would have received the credentials.
The blog post includes the full AES-256 decryption key and IV for the firmware — hardcoded identically across the entire camera line — making it possible for anyone to extract and inspect the firmware of all affected models. The researcher, who discovered the token using the open-source secret scanner TruffleHog, closed with a plea: "We really gotta stop making these mistakes so often. How am I supposed to be sleeping at night?"
Sources: Researcher's blog post (hhh.hn), Hacker News discussion (576 points, 188 comments)
安全摄像头固件在登录页面包含GitHub管理员令牌
对 hanwha vision 安全摄像头的固件逆向分析揭露了一个具有数百个仓库管理员权限[K 的 github 访问令牌——嵌入在用户界面中,并且提供给加载摄像机登录页面的所有人。
← 日更新 Hourly · 2026-07-25 08:00 UTC 安全摄像头固件在其登录页面中包含GitH[4D[K GitHub管理员令牌 Image: Jerryzhu2004, CC BY-SA 4.0 (许可) 一名安全研究员拆解[K Hanwha Vision安全摄像头时发现,其登录页面内嵌了一个可访问数百个仓库的GitHub[6D[K GitHub管理员令牌。
More Hourlies Stories
Content on Anagnorisis is summarized, paraphrased, and editorialized from publicly available sources for length and clarity. Original sources are linked where available. All trademarks belong to their respective owners.
