Aggregates CVE and security vulnerability intelligence across all hanwhavision-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk cross-site scripting and vendor risk input validation and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-8075 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered that validation of incoming XML format request messages is inadequate. This vulnerability could allow an attacker to XSS on the user's browser. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds. | fc9afe74-3f80-4fb7-a313-e6f036a89882 | 5.8 | 0.02% | 2025-12-26 | 2026-01-07 |
| CVE-2025-52601 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a vulnerability in Device Manager that a hardcoded encryption key for sensitive information. An attacker can use key to decrypt sensitive information. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds. | fc9afe74-3f80-4fb7-a313-e6f036a89882 | 6.3 | 0.01% | 2025-12-26 | 2026-01-07 |
| CVE-2025-52600 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a vulnerability in camera video analytics that Improper input validation. This vulnerability could allow an attacker to execute specific commands on the user's host PC.The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds. | fc9afe74-3f80-4fb7-a313-e6f036a89882 | 5.2 | 0.04% | 2025-12-26 | 2026-01-07 |
| CVE-2025-52599 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered Inadequate of permission management for camera guest account. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds. | fc9afe74-3f80-4fb7-a313-e6f036a89882 | 6.3 | 0.04% | 2025-12-26 | 2026-01-07 |
| CVE-2025-52598 | Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has found a flaw that camera's client service does not perform certificate validation. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds. | fc9afe74-3f80-4fb7-a313-e6f036a89882 | 6.3 | 0.02% | 2025-12-26 | 2026-01-16 |
| CVE-2023-5038 | badmonkey, a Security Researcher has found a flaw that allows for a unauthenticated DoS attack on the camera. An attacker runs a crafted URL, nobody can access the web management page of the camera. and must manually restart the device or re-power it. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds. | fc9afe74-3f80-4fb7-a313-e6f036a89882 | 8.7 | 0.40% | 2024-06-25 | 2024-11-21 |
| CVE-2023-5747 | Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation of Wave on the camera device. The Wave server application in camera device was vulnerable to command injection allowing an attacker to run arbitrary code. HanwhaVision has released patched firmware for the highlighted flaw. Please refer to the hanwhavision security report for more information and solution." | fc9afe74-3f80-4fb7-a313-e6f036a89882 | 7.2 | 0.34% | 2023-11-13 | 2024-11-21 |
| CVE-2023-5037 | badmonkey, a Security Researcher has found a flaw that allows for a authenticated command injection on the camera. An attacker could inject malicious into request packets to execute command. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds. | fc9afe74-3f80-4fb7-a313-e6f036a89882 | 7.1 | 0.48% | 2023-11-13 | 2024-11-21 |
| CVE-2023-31996 | Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Command Injection due to improper sanitization of special characters for the NAS storage test function. | [email protected] | 8.8 | 2.56% | 2023-05-23 | 2025-01-17 |
| CVE-2023-31995 | Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Cross Site Scripting (XSS). | [email protected] | 5.4 | 0.59% | 2023-05-23 | 2025-01-17 |
| CVE-2023-31994 | Certain Hanwha products are vulnerable to Denial of Service (DoS). ck vector is: When an empty UDP packet is sent to the listening service, the service thread results in a non-functional service (DoS) via WS Discovery and Hanwha proprietary discovery services. This affects IP Camera ANE-L7012R 1.41.01 and IP Camera XNV-9082R 2.10.02. | [email protected] | 5.3 | 0.52% | 2023-05-23 | 2025-01-17 |