ZeroHour

CVE-2020-5735

KEV PoC large

Stack-Based Buffer Overflow in Amcrest Cameras and NVRs Allows Remote DoS and RCE

CISA: Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability

CVSS 3.1
8.8 high
EPSS
36%p98
Published
()
KEV added
AI analysis

Amcrest cameras and network video recorders (NVRs) contain a stack-based buffer overflow (CWE-121) in the service that listens on TCP port 37777, the vendor's proprietary command/communication port. An unauthenticated, remote attacker can trigger the flaw by sending crafted data to port 37777, overflowing a stack buffer. Successful exploitation can crash the device (denial of service) and possibly allow arbitrary code execution on the camera or NVR. Any Amcrest camera or NVR whose port 37777 is reachable — especially devices port-forwarded to or directly exposed to the internet — is affected; the available data does not specify affected firmware version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, indicating confirmed in-the-wild exploitation, and its EPSS score of 36.2% (98th percentile) indicates a high near-term exploitation probability, though no public proof-of-concept is known.

What to do: Apply Amcrest firmware updates per the vendor's instructions, as required by CISA's KEV listing. Until patched, remove internet port forwards for TCP 37777 and restrict access to trusted management networks or a VPN. Check whether port 37777 is exposed on your devices and watch for unexplained crashes or reboots, which can indicate exploitation attempts.

Affected
Amcrest Cameras and Network Video Recorder (NVR)
Estimated exposure
largetens of thousands of internet-exposed devices (10k–100k), with a larger installed base behind NAT — Public internet-wide scans (e.g., Shodan/Censys) of Amcrest/Dahua's TCP 37777 service typically show tens of thousands of exposed devices, while Amcrest's consumer/prosumer installed base is substantially larger but mostly hidden behind…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.

CISA Known Exploited Vulnerability
Affected
Amcrest Cameras and Network Video Recorder (NVR)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
amcrest
Products
1080-lite 8ch firmware, amdv10814-h5 firmware, ipm-721 firmware, ip2m-841 firmware, ip2m-841-v3 firmware, ip2m-853ew firmware, ip2m-858w firmware, ip2m-866w firmware, ip2m-866ew firmware, ip4m-1053ew firmware, ip8m-2454ew firmware, ip8m-2493eb firmware
Weakness
CWE-121, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.