Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Police Body Camera Apps Sending Data to Cloud Servers Hosted in China Via TLS Port 9091

Posted on September 9, 2025September 9, 2025 By CWS

Police-issued physique cameras have turn into ubiquitous instruments for recording regulation enforcement encounters, but a current investigation has uncovered troubling design selections in a budget-friendly system that compromise each privateness and knowledge integrity.

The Viidure cellular utility, designed to switch video proof from the digital camera’s onboard Wi-Fi hotspot to cloud servers, was discovered to speak over a nonstandard TLS port, directing delicate info to servers based mostly in China.

This conduct raises important considerations for departments counting on these gadgets to supply court-admissible proof.

Preliminary visitors captures revealed that the cellular app establishes TLS connections to app-api.lufengzhe.com:9091, alongside geolocation API calls to api.map.baidu.com:443 and loc.map.baidu.com:443.

Digital camera (Supply – Brown Positive Safety)

Whois queries confirmed that the first endpoint at 115.175.147.124 is owned by Huawei Worldwide Pte. Ltd. and originates from a Chinese language community block.

Using port 9091—unusual for HTTPS visitors—alerts an try to obscure routine knowledge flows, doubtlessly evading network-based monitoring instruments.

Brown Positive Safety analysts famous that the app’s reliance on improperly validated server certificates enabled an easy man-in-the-middle (MitM) assault.

By injecting solid certificates through a customized mitmrouter setup, researchers had been capable of intercept plaintext HTTP exchanges throughout the TLS tunnel.

Such misconfigurations not solely expose metadata like IMEI numbers and usernames but additionally threaten the confidentiality of recorded video streams.

Mitmrouter diagram (Supply – Brown Positive Safety)

Past mere metadata, the intercepted payloads embrace machine identifiers and utility model particulars.

The next snippet illustrates the HTTP POST request captured in the course of the MitM session:-

POST /iot/api/v1/model/verify HTTP/1.1
Host: app-api.lufengzhe.com:9091
Content material-Kind: utility/json
srapi_imei: 17562212185897060
srapi_time: 1757047550015

{
“knowledge”: [
{
“model”: “6zhentan_android”,
“version”: “v2.7.1.250712”,
“imei”: “17562212185897060”
}
],
“username”: “”
}

An infection Mechanism and Information Exfiltration

The Viidure utility doesn’t self-install malware however features as an inadvertent exfiltration vector as a result of its insecure communications design.

Upon pairing with the digital camera’s hotspot, the app robotically initiates background knowledge uploads with out consumer notification.

TLS connections to the Chinese language endpoint are established instantly, transmitting figuring out info alongside any captured media metadata.

Using port 9091 seems deliberate, more likely to bypass typical TLS inspection guidelines that concentrate on ports 443 and 8443.

Persistence of this conduct stems from the applying’s versioning system. Each time the app checks for updates—triggered at startup and periodically throughout use—it reaffirms the connection to the malicious endpoint.

With out rigorous certificates validation or consumer consent dialogs, departmental networks could stay unaware of routine knowledge streams exiting to unauthorized servers.

Safety groups ought to prioritize community segmentation and deep packet inspection guidelines that embrace nonstandard ports to detect and disrupt related knowledge flows.

Increase your SOC and assist your workforce shield your enterprise with free top-notch risk intelligence: Request TI Lookup Premium Trial.

Cyber Security News Tags:Apps, Body, Camera, China, Cloud, Data, Hosted, Police, Port, Sending, Servers, TLS

Post navigation

Previous Post: Microsoft Anti-Spam Bug Blocks Users From Opening URLs in Exchange Online and Teams
Next Post: Critical Ivanti Endpoint Manager Vulnerabilities Let Attackers Execute Remote Code

Related Posts

CISA Warns of Git Arbitrary File Write Vulnerability Exploited in Attacks Cyber Security News
Mustang Panda Using New DLL Side-Loading Technique to Deliver Malware Cyber Security News
Meta’s Llama Firewall Bypassed Using Prompt Injection Vulnerability Cyber Security News
Threat Actors Weaponizing SVG Files to Embed Malicious JavaScript Cyber Security News
Trend Micro Apex One Vulnerability Allow Attackers to Inject Malicious Code Cyber Security News
Threat Actors Allegedly Listed Windows Zero-Day RCE Exploit For Sale on Dark Web Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • 706,000+ BIND 9 Resolver Instances Vulnerable to Cache Poisoning Exposed Online
  • LockBit 5.0 Actively Attacking Windows, Linux, and ESXi Environments
  • Hackers Weaponizing Telegram Messenger with Dangerous Android Malware to Gain Full System Control
  • Vault Viper Exploits Online Gambling Websites Using Custom Browser to Install Malicious Program
  • Google Warns of Threat Actors Using Fake Job Posting to Deliver Malware and Steal Credentials

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • 706,000+ BIND 9 Resolver Instances Vulnerable to Cache Poisoning Exposed Online
  • LockBit 5.0 Actively Attacking Windows, Linux, and ESXi Environments
  • Hackers Weaponizing Telegram Messenger with Dangerous Android Malware to Gain Full System Control
  • Vault Viper Exploits Online Gambling Websites Using Custom Browser to Install Malicious Program
  • Google Warns of Threat Actors Using Fake Job Posting to Deliver Malware and Steal Credentials

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News