The device can send nativ key commands because it is registered as a HID. This works completely without any control software if you have a shell access on the device:
Einstein2150 发表于 2025-10-10 12:52
There is a vulnerability. I'm root on the device. I wrote 2 mails in 1 week to ULANZI but no react ...
alright... i don't know if the vendor will fix it
if not, can you share how did you get the bash script hacked into the system? i'd like to customised the device a little bit
thanks!
I'll try have a look on the unauthenticated path myself
but i agree that how the auth data the software handled is really bad, just plain text stored locally