Missing User Warnings
Medium
- Confidence
- 79% confidence
- Finding
- The documentation shows multiple features handling sensitive credentials and telemetry insecurely or ambiguously, including plain FTP credentials, Wi-Fi passwords, RTSP/ONVIF credentials in JSON, and HTTP/MQTT notification targets with tokens. In the context of an embedded device API reference, normalizing these patterns without transport-security guidance increases the chance integrators will deploy secrets over plaintext channels or log them unsafely, leading to credential disclosure and device compromise.
