anagnorisis.cloudSign in

← Hourlies

Hourly ·

Security Camera Firmware Shipped with GitHub Admin Token on Its Login Page

A firmware teardown of Hanwha Vision security cameras revealed a GitHub token with admin access to hundreds of repositories — baked into the UI and served to anyone who loaded the camera's login page.

Security Camera Firmware Shipped with GitHub Admin Token on Its Login Page
Image: Jerryzhu2004, CC BY-SA 4.0 (license)

A security researcher tearing down firmware from Hanwha Vision cameras has discovered something startling: a live GitHub token with admin privileges to hundreds of repositories, embedded in the camera's web login page and served to anyone who accessed it.

The researcher — who reverse-engineered the firmware encryption by feeding the camera's upgrade binary to an AI coding agent — found the token duplicated across roughly 30 files in the camera's root filesystem. The token was leaking because the company's Vite build process was capturing the entire CI environment — including GitHub credentials — and baking them into the production JavaScript bundle. Anyone who loaded the camera's admin interface in a browser received the token over the wire.

The token granted administrative access to Hanwha's entire GitHub organization: hundreds of repositories, with full read/write permissions. Even more concerning, the CI environment contained environment variables referencing IP addresses assigned to the U.S. Department of Defense. Hanwha Group's defense subsidiaries — including Hanwha Aerospace and Hanwha Defense USA — manufacture artillery systems, autonomous sentry guns, and armored vehicle subsystems, raising the possibility that the leaked token sat at the intersection of commercial surveillance and military supply chains.

After scraping approximately 500 firmware images across Hanwha's camera lineup and successfully extracting 62% of them, the researcher confirmed the same GitHub token appeared in three camera models. Hanwha responded within 12 hours of disclosure and revoked the token. No evidence of exploitation was found, though the researcher noted that anyone who had ever accessed a vulnerable camera's web interface would have received the credentials.

The blog post includes the full AES-256 decryption key and IV for the firmware — hardcoded identically across the entire camera line — making it possible for anyone to extract and inspect the firmware of all affected models. The researcher, who discovered the token using the open-source secret scanner TruffleHog, closed with a plea: "We really gotta stop making these mistakes so often. How am I supposed to be sleeping at night?"

Sources: Researcher's blog post (hhh.hn), Hacker News discussion (576 points, 188 comments)

More Hourlies Stories

Content on Anagnorisis is summarized, paraphrased, and editorialized from publicly available sources for length and clarity. Original sources are linked where available. All trademarks belong to their respective owners.

More from Anagnorisis