Vulnerability resides in D-Link source code file called boa web server request request request.c is handling the HTTP request to the camera. The only place the only place encrypted the traffic is encrypted. But some of the other sensitive content such as camera IP and MAC addresses, video and audio streams, and extensive camera info are passing through the unencrypted tunnel. This flaw could allows an attacker to perform a Man-in-the-Middle attack and intercept the connection to spy on victims video streams.”]

