CVE-2024-42531
https://notcve.org/view.php?id=CVE-2024-42531
23 Aug 2024 — Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a specific set of URLs that can be used to redirect the camera feed. Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a specific set of URLs that can be used to redirect the camera feed. NOTE: the vendor's perspective is that the Anonymous120386 sample code can establi... • http://ezviz.com • CWE-20: Improper Input Validation •
CVE-2024-41623
https://notcve.org/view.php?id=CVE-2024-41623
13 Aug 2024 — An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload • http://d3d.com • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2024-4063 – EZVIZ CS-C6-21WFR-8 Davinci Application certificate validation
https://notcve.org/view.php?id=CVE-2024-4063
23 Apr 2024 — A vulnerability was found in EZVIZ CS-C6-21WFR-8 5.2.7 Build 170628. It has been classified as problematic. This affects an unknown part of the component Davinci Application. The manipulation leads to improper certificate validation. It is possible to initiate the attack remotely. • https://github.com/kzLiu2017/CVE_Document/blob/main/CVE_%20advisory_ezviz.pdf • CWE-295: Improper Certificate Validation •
CVE-2023-48121
https://notcve.org/view.php?id=CVE-2023-48121
28 Nov 2023 — An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 20230401, Ezviz CS-CV310-xxx prior to v5.3.x build 20230401, Ezviz CS-C6CN-xxx prior to v5.3.x build 20230401, Ezviz CS-C3N-xxx prior to v5.3.x build 20230401 allows remote attackers to obtain sensitive information by sending crafted messages to the affected devices. Una vulnerabilidad de omisión de autenticación en Direct Connection Module en Ezviz CS-C6N-xxx anterior a v5.3.x compilación 202304... • https://joerngermany.github.io/ezviz_vulnerability • CWE-287: Improper Authentication •
CVE-2023-41613 – EzViz Studio 2.2.0 DLL Hijacking
https://notcve.org/view.php?id=CVE-2023-41613
15 Nov 2023 — EzViz Studio v2.2.0 is vulnerable to DLL hijacking. EzViz Studio v2.2.0 es vulnerable al secuestro de DLL. EzViz Studio version 2.2.0 suffers from a dll hijacking vulnerability. • https://packetstorm.news/files/id/175684 • CWE-427: Uncontrolled Search Path Element •
CVE-2023-34552
https://notcve.org/view.php?id=CVE-2023-34552
01 Aug 2023 — In certain EZVIZ products, two stack based buffer overflows in mulicast_parse_sadp_packet and mulicast_get_pack_type functions of the SADP multicast protocol can allow an unauthenticated attacker present on the same local network as the camera to achieve remote code execution. This affects CS-C6N-B0-1G2WF Firmware versions before V5.3.0 build 230215 and CS-C6N-R101-1G2WF Firmware versions before V5.3.0 build 230215 and CS-CV310-A0-1B2WFR Firmware versions before V5.3.0 build 230221 and CS-CV310-A0-1C2WFR-C ... • http://ezviz.com • CWE-787: Out-of-bounds Write •
CVE-2023-34551
https://notcve.org/view.php?id=CVE-2023-34551
01 Aug 2023 — In certain EZVIZ products, two stack buffer overflows in netClientSetWlanCfg function of the EZVIZ SDK command server can allow an authenticated attacker present on the same local network as the camera to achieve remote code execution. This affects CS-C6N-B0-1G2WF Firmware versions before V5.3.0 build 230215 and CS-C6N-R101-1G2WF Firmware versions before V5.3.0 build 230215 and CS-CV310-A0-1B2WFR Firmware versions before V5.3.0 build 230221 and CS-CV310-A0-1C2WFR-C Firmware versions before V5.3.2 build 2302... • http://ezviz.com • CWE-787: Out-of-bounds Write •
CVE-2022-2472 – Improper Initialization vulnerability in local server authentication logic
https://notcve.org/view.php?id=CVE-2022-2472
15 Sep 2022 — Improper Initialization vulnerability in the local server component of EZVIZ CS-C6N-A0-1C2WFR allows a local attacker to read the contents of the memory space containing the encrypted admin password. This issue affects: EZVIZ CS-C6N-A0-1C2WFR versions prior to 5.3.0 build 220428. Una vulnerabilidad de inicialización inapropiada en el componente del servidor local de EZVIZ CS-C6N-A0-1C2WFR, permite a un atacante local leer el contenido del espacio de memoria que contiene la contraseña de administrador cifrad... • https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-ezviz-smart-cams • CWE-665: Improper Initialization •
CVE-2022-2471 – Stack-Based Buffer Overflow Vulnerability in the EZVIZ Motion Detection component
https://notcve.org/view.php?id=CVE-2022-2471
15 Sep 2022 — Stack-based Buffer Overflow vulnerability in the EZVIZ Motion Detection component as used in camera models CS-CV248, CS-C6N-A0-1C2WFR, CS-DB1C-A0-1E2W2FR, CS-C6N-B0-1G2WF, CS-C3W-A0-3H4WFRL allows a remote attacker to execute remote code on the device. This issue affects: EZVIZ CS-CV248 versions prior to 5.2.3 build 220725. EZVIZ CS-C6N-A0-1C2WFR versions prior to 5.3.0 build 220428. EZVIZ CS-DB1C-A0-1E2W2FR versions prior to 5.3.0 build 220802. EZVIZ CS-C6N-B0-1G2WF versions prior to 5.3.0 build 220712. • https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-ezviz-smart-cams • CWE-121: Stack-based Buffer Overflow •