All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication. This includes the XMeye service and firmware update communication. This could allow an attacker to eavesdrop on video feeds, steal XMeye login credentials, or impersonate the update server with malicious update code.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HXiongmaitech Xmeye P2p Cloud Server
APPXiongmaitechall versions
Related vulnerabilities
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC ...
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an u...
Authentication bypass w kamerach IP Xiongmai XM530 — dostęp bez uwierzytelnienia
Stack-based buffer overflow w urządzeniach NVR Xiongmai — RCE bez uwierzytelnienia
Backdoor w firmware urządzeń Xiongmai — statyczne dane konta root