A Stack-based Buffer Overflow issue was discovered in Xiongmai Technology IP Cameras and DVRs using the NetSurveillance Web interface. The stack-based buffer overflow vulnerability has been identified, which may allow an attacker to execute code remotely or crash the device. After rebooting, the device restores itself to a more vulnerable state in which Telnet is accessible.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HXiongmaitech Ahb7004t Gl V4
HWXiongmaitechall versionsXiongmaitech Ahb7004t Gl V4 Firmware
OSXiongmaitech4.02.r11.7601Xiongmaitech Ahb7004t Gs V3
HWXiongmaitechall versionsXiongmaitech Ahb7004t Gs V3 Firmware
OSXiongmaitech4.02.r11.7601Xiongmaitech Ahb7004t G V4
HWXiongmaitechall versionsXiongmaitech Ahb7004t G V4 Firmware
OSXiongmaitech4.02.r11.7601Xiongmaitech Ahb7004t H V2
HWXiongmaitechall versionsXiongmaitech Ahb7004t H V2 Firmware
OSXiongmaitech4.02.r11.7601Xiongmaitech Ahb7004t Lme V3
HWXiongmaitechall versionsXiongmaitech Ahb7004t Lme V3 Firmware
OSXiongmaitech4.02.r11.7601Xiongmaitech Ahb7004t Lm V3
HWXiongmaitechall versionsXiongmaitech Ahb7004t Lm V3 Firmware
OSXiongmaitech4.02.r11.3070Xiongmaitech Ahb7004t Mh V2
HWXiongmaitechall versionsXiongmaitech Ahb7004t Mh V2 Firmware
OSXiongmaitech4.02.r11.7601Xiongmaitech Ahb7004t Mh V3
HWXiongmaitechall versionsXiongmaitech Ahb7004t Mh V3 Firmware
OSXiongmaitech4.02.r11.7601Xiongmaitech Ahb7008f2 G V4
HWXiongmaitechall versionsXiongmaitech Ahb7008f2 G V4 Firmware
OSXiongmaitech4.02.r11.7601Xiongmaitech Ahb7008f2 H
HWXiongmaitechall versionsXiongmaitech Ahb7008f2 H Firmware
OSXiongmaitech4.02.r11.3070Xiongmaitech Ahb7008f4 G V4
HWXiongmaitechall versionsXiongmaitech Ahb7008f4 G V4 Firmware
OSXiongmaitech4.02.r11.7601Xiongmaitech Ahb7008f4 H
HWXiongmaitechall versionsXiongmaitech Ahb7008f4 H Firmware
OSXiongmaitech4.02.r11.3070Xiongmaitech Ahb7008f8 G V4
HWXiongmaitechall versionsXiongmaitech Ahb7008f8 G V4 Firmware
OSXiongmaitech4.02.r11.7601Xiongmaitech Ahb7008f8 H
HWXiongmaitechall versionsXiongmaitech Ahb7008f8 H Firmware
OSXiongmaitech4.02.r11.3070Xiongmaitech Ahb7008t4 H V2
OSXiongmaitech_firmwareXiongmaitech Ahb7008t4 H V2 Firmware
OSXiongmaitech4.02.r11.7601
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
Related vulnerabilities
CVE-2021-41506CRITICAL9.8PL ✓same product
Backdoor w firmware urządzeń Xiongmai — statyczne dane konta root
CVE-2020-22253CRITICAL9.8PL ✓same product
Xiongmai Technology: otwarty port 9530 umożliwia nieautoryzowany dostęp Telnet
CVE-2025-65856CRITICAL9.8PL ✓same vendor
Authentication bypass w kamerach IP Xiongmai XM530 — dostęp bez uwierzytelnienia
CVE-2022-45460CRITICAL9.8PL ✓same vendor
Stack-based buffer overflow w urządzeniach NVR Xiongmai — RCE bez uwierzytelnienia
CVE-2018-17915CRITICAL9.8PL ✓same vendor
Brak szyfrowania komunikacji w Xiongmai XMeye P2P Cloud Server