CRITICAL🇵🇱 Wersja polska

CVE-2018-17915

CVSS 9.8v3.0pub. 2018-10-10upd. 2024-11-21

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication. This includes the XMeye service and firmware update communication. This could allow an attacker to eavesdrop on video feeds, steal XMeye login credentials, or impersonate the update server with malicious update code.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Xiongmaitech Xmeye P2p Cloud Server

    APP
    Xiongmaitech
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2018-17917MEDIUM5.3same product

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC ...

CVE-2018-17919MEDIUM6.5same product

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an u...

CVE-2025-65856CRITICAL9.8PL ✓same vendor

Authentication bypass w kamerach IP Xiongmai XM530 — dostęp bez uwierzytelnienia

CVE-2022-45460CRITICAL9.8PL ✓same vendor

Stack-based buffer overflow w urządzeniach NVR Xiongmai — RCE bez uwierzytelnienia

CVE-2021-41506CRITICAL9.8PL ✓same vendor

Backdoor w firmware urządzeń Xiongmai — statyczne dane konta root