Tim Philipp Schäfers (TPS)
Founder & CEO of Mint Secure GmbH: https://mint-secure.de/
Member of Chaos Computer Club and OWASP
Protecting what matters in a connected world
Session
In late 2024, we discovered a critical path traversal vulnerability (CVE-2025-43928) affecting Media Relay Service (MRS), a software platform used worldwide in surveillance and reconnaissance systems manufactured by Infodraw. The affected ecosystem includes mobile video surveillance solutions, police body cameras, covert observation equipment, and drone-based reconnaissance platforms operated by law enforcement agencies and governmental organizations - including the Unité Spéciale de la Police in Luxembourg.
The vulnerability allowed unauthenticated attackers to access arbitrary files on affected Windows and Linux systems and, under certain circumstances, delete files remotely. Through internet-wide scanning and coordinated vulnerability disclosure efforts, vulnerable systems were identified across multiple countries, including systems attributed to specialized police units and operational surveillance teams.
This presentation will cover the technical analysis of the vulnerability, the methodology used to identify exposed systems, challenges encountered during responsible disclosure when the vendor remained unresponsive, and the coordination with national CERTs and affected operators. The talk will further discuss how a successful disclosure process ultimately resulted in a criminal investigation (in Luxembourg) against the reporting researcher, despite the affected system being secured following notification.
Using this case study, we will examine the growing tension between cybersecurity research, public-interest vulnerability disclosure, law enforcement operations, and outdated computer crime legislation. The presentation aims to provide practical lessons for vulnerability researchers, CERT teams, and policymakers while highlighting the need for legal certainty for security research in Europe.
More information:
English: https://mint-secure.de/path-traversal-vulnerability-in-surveillance-software/
German: https://mint-secure.de/ermittlungsverfahren-nach-meldung-von-it-sicherheitsluecken-in-observationssystemen/
German: https://mint-secure.de/path-traversal-sicherheitsluecke-aufklaerungsgeraete/