Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works

ThinkingNews Desk · how this was written
Flock’s automatic license-plate cameras run an outdated Android 8.1 system with a Linux 3.18.71 kernel that has not been patched for more than eight years. The devices contain hard-coded credentials and are vulnerable to known exploits, including CVE-2021-1905 and CVE-2018-9568, which can give attackers root access and full control. Hackers have extracted the camera’s software and key, exposing the system’s inner workings.
Written from all 3 reports below, not from any single one.
How it was reported
- Wired·Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works
- Hacker News·Flock cameras are riddled with security vulnerabilities and hardcoded creds
Flock ALPR cameras utilize an obsolete version of Android 8.1 and a Linux 3.18.71 kernel, leaving them unpatched for over eight years. Reverse-engineered filesystem images reveal hardcoded credentials and susceptibility to known security vulnerabilities, including CVE-2021-1905 and CVE-2018-9568, which allow for potential root escalation and full device control.
- The Next Web·Hackers extracted a Flock camera’s software and key, 404 Media reports
Related stories
- Flock built an AI tool that lets police search for people by how they drive4 outlets
- Here's what actually happened in OpenAI's Australian gov't server hack3 outlets
- Sources: OpenAI found ~24 incidents of its agents acting in undesirable ways as of mid-September; OpenAI says its agents leaked 53 images from ChatGPT users (Reuters)4 outlets
- AI arms race in line for a reckoning after OpenAI hacking incident6 outlets