Lucene search

K

Xiongmaitech Security Vulnerabilities

cve
cve

CVE-2023-39068

Buffer Overflow vulnerability in NBD80S09S-KLC v.YK_HZXM_NBD80S09S-KLC_V4.03.R11.7601.Nat.OnvifC.20230414.bin and NBD80N32RA-KL-V3 v.YK_HZXM_NBD80N32RA-KL_V4.03.R11.7601.Nat.OnvifC.20220120.bin allows a remote attacker to casue a denial of service via a crafted request to the service.XM...

7.5CVSS

7.3AI Score

0.001EPSS

2023-09-11 07:15 PM
22
cve
cve

CVE-2021-41506

Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4.02.R11.7601.Nat.Onvif.20170424, V4.02.R11.Nat.Onvif.20170327, V4.02.R11.Nat.Onvif.20161205,...

9.8CVSS

9.3AI Score

0.003EPSS

2022-06-30 01:15 PM
49
5
cve
cve

CVE-2022-45460

Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow an unauthenticated and remote user to exploit a stack-based buffer overflow and crash the web server, resulting in a system reboot. An...

9.8CVSS

9.7AI Score

0.022EPSS

2023-03-28 10:15 PM
82
cve
cve

CVE-2022-45045

Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and authenticated...

8.8CVSS

8.8AI Score

0.003EPSS

2022-12-01 05:15 AM
39
In Wild
cve
cve

CVE-2021-38828

Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to plain-text traffic...

5.3CVSS

5.3AI Score

0.001EPSS

2022-11-14 02:15 AM
25
9
cve
cve

CVE-2021-38827

Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to account...

7.5CVSS

7.5AI Score

0.001EPSS

2022-11-14 02:15 AM
22
5
cve
cve

CVE-2020-22253

Xiongmai Technology Co devices AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, and HI3518E_50H10L_S39 were all discovered to have port 9530 open which allows unauthenticated attackers to make arbitrary Telnet connections with the victim...

9.8CVSS

9.6AI Score

0.002EPSS

2022-04-06 11:15 PM
39
cve
cve

CVE-2022-26259

A buffer over flow in Xiongmai DVR devices NBD80X16S-KL, NBD80X09S-KL, NBD80X08S-KL, NBD80X09RA-KL, AHB80X04R-MH, AHB80X04R-MH-V2, AHB80X04-R-MH-V3, AHB80N16T-GS, AHB80N32F4-LME, and NBD90S0VT-QW allows attackers to cause a Denial of Service (DoS) via a crafted RSTP...

7.8CVSS

7.4AI Score

0.0005EPSS

2022-03-28 01:15 AM
67
2
cve
cve

CVE-2019-11878

An issue was discovered on XiongMai Besder IP20H1 V4.02.R12.00035520.12012.047500.00200 cameras. An attacker on the same local network as the camera can craft a message with a size field larger than 0x80000000 and send it to the camera, related to an integer overflow or use of a negative number....

6.5CVSS

6.5AI Score

0.001EPSS

2019-05-10 03:29 PM
33
cve
cve

CVE-2018-17917

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potential Cloud IDs. Using this ID, the attacker can discover and connect to valid devices using one of the supported...

5.3CVSS

7AI Score

0.001EPSS

2018-10-10 03:29 PM
105
cve
cve

CVE-2018-17915

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication. This includes the XMeye service and firmware update communication. This could allow an attacker to eavesdrop on video feeds, steal XMeye login credentials, or impersonate the...

9.8CVSS

9.3AI Score

0.002EPSS

2018-10-10 03:29 PM
184
cve
cve

CVE-2018-17919

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with its default password to login to XMeye and access/view video...

6.5CVSS

7.9AI Score

0.001EPSS

2018-10-10 03:29 PM
89
cve
cve

CVE-2018-10088

Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than...

9.8CVSS

9.4AI Score

0.022EPSS

2018-06-08 12:29 PM
139
In Wild
cve
cve

CVE-2017-16725

A Stack-based Buffer Overflow issue was discovered in Xiongmai Technology IP Cameras and DVRs using the NetSurveillance Web interface. The stack-based buffer overflow vulnerability has been identified, which may allow an attacker to execute code remotely or crash the device. After rebooting, the...

9.8CVSS

9.6AI Score

0.004EPSS

2017-12-20 07:29 PM
198
In Wild
cve
cve

CVE-2017-7577

XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP...

9.8CVSS

9.3AI Score

0.005EPSS

2017-04-07 04:59 AM
44