An attacker could exploit the mobile application to do the following:
- Eavesdrop on API calls
- Access local resources on the mobile device
- Expose sensitive user details
- Locate sensitive information for all users in clear text on the mobile device
- Dump database contents via SQL(ite) injection
- Perform arbitrary script execution via WebView JavaScript interface
- Gain access to other user accounts
- Track users in the vendor's cloud environment
- Expose camera playback feeds stored on the device
- Delete camera playback feeds
- Change user information
- Add users for sharing cameras without authorization
- Create long-lived sessions that do not expire for persistent access
- Take screenshots and send them to a third party