Besder 6004mw-xma201 wifi not working

Terrorr

n3wb
Jan 22, 2022
2
3
Poland
Has anyone using BESDER cameras from ali ? I have two cameras type 6004mw-xma201. After firmware update (online update from XMEYE app) wifi stopped working ...
I didn't wrote factory installed firmware and now I don't know which version should I use.

BESDER support is useless, from 03.01.2022 they trying to dispose me saying to check wifi signal etc ...

When searching wifi in CMS, VMS or camera webpage I'm getting info "unable to get config". Camera hang and need to be rebooted.

Now app is showing firmware in attached picture, for sure it was version V4...
 

Attachments

  • 268513542_1539352139768774_8319170817407712099_n.jpg
    268513542_1539352139768774_8319170817407712099_n.jpg
    128.6 KB · Views: 8
Note that in your image, it states "Cloud Status" as "Connecting Success" which may concern you ==>> Millions Of Xiongmai Video Surveillance Devices Can Be Hacked Via Cloud Feature (Xmeye P2p Cloud)

Note also that in the article Xiongmai is the OEM for Besder cameras. :blankstare:

P.S. - Welcome to IPCT !

Hello Tony,

thanks for interesting articule ! Cloud status was success due to LAN connection ( I connected it olny to make a screenshot from APP).

I will stop using could feature and will connect it to internal network (and use home assistant), but first need to get old firmware to check if it infected or not...

Thanks for supporting !

Best regards
Łukasz
 
Note that in your image, it states "Cloud Status" as "Connecting Success" which may concern you ==>> Millions Of Xiongmai Video Surveillance Devices Can Be Hacked Via Cloud Feature (Xmeye P2p Cloud)

Note also that in the article Xiongmai is the OEM for Besder cameras. :blankstare:

P.S. - Welcome to IPCT !
Lot of misses from a rather cheap manufacturer from China, but they can easily fix the bugs and move on. After all, there aren't that many NVR builders around the world, so they do have their slice from the market for sure.

Isn't similar scenarios possible with Dahua, Hikvision, Tuya and all other cloud-based services for NVR/cameras remote viewing? I know that is difficult to respect GDPR and update your own cloud fast enough. Even Amazon has few security flaws from time to time with its Ring/Blink devices, but this is valid for every device that can be accessed from cloud.

Now strictly on the above link, the scenario on Xiongmai devices is based on not changing the default credentials shipped with the NVR and cameras and about a possible existence of a 2nd account with already known credentials, so easy to counter-fight for even an average consumer.

What it matters is to have all the default credentials updated with a strong password on both NVR and IP cameras, NVR/cameras should not be exposed (NAT) to Internet, not even by port forwarding, DDNS not enabled on the NVR/cameras and other common-sense things that can be easily done by anyone before using remote access on NVR or IP cameras.

I'm sure that Xiongmai did upgraded their cloud security since 2018. I am now testing one such NVR and I am pleased with how it works. The 2nd account is missing and default password is different from one OEM integrator to another. Also, in the manual it states that default credentials should be changed.