ZeroHour

Vulnerabilities

12 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-5736
Amcrest cameras and NVR are vulnerable to a null pointer dereference over port 37777.

Amcrest cameras and NVR are vulnerable to a null pointer dereference over port 37777. An authenticated remote attacker can abuse this issue to crash the device.

NVD description · AI analysis pending
6.52%
  • amcrest 1080-lite 8ch firmware
  • amcrest amdv10814-h5 firmware
  • amcrest ipm-721 firmware
  • +1 more
CVE-2020-5735
Stack-Based Buffer Overflow in Amcrest Cameras and NVRs Allows Remote DoS and RCE

Amcrest cameras and network video recorders (NVRs) contain a stack-based buffer overflow (CWE-121) in the service that listens on TCP port 37777, the vendor's proprietary command/communication port. An unauthenticated, remote attacker can trigger the flaw by sending crafted data to port 37777, overflowing a stack buffer. Successful exploitation can crash the device (denial of service) and possibly allow arbitrary code execution on the camera or NVR. Any Amcrest camera or NVR whose port 37777 is reachable — especially devices port-forwarded to or directly exposed to the internet — is affected; the available data does not specify affected firmware version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, indicating confirmed in-the-wild exploitation, and its EPSS score of 36.2% (98th percentile) indicates a high near-term exploitation probability, though no public proof-of-concept is known.

Do: Apply Amcrest firmware updates per the vendor's instructions, as required by CISA's KEV listing. Until patched, remove internet port forwards for TCP 37777 and restrict access to trusted management networks or a VPN. Check whether port 37777 is exposed on your devices and watch for unexplained crashes or reboots, which can indicate exploitation attempts.

8.836% KEV PoC
  • Amcrest Cameras and Network Video Recorder (NVR)
largetens of thousands of internet-exposed devices (10k–100k), with a larger installed base behind NAT
CVE-2020-7222
An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504.

An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to authenticate. An attacker who changes the result parameter (to true) in this JavaScript code can bypass authentication and achieve limited privileges (ability to see every option but not modify them).

NVD description · AI analysis pending
5.31% PoC
  • amcrest web server
CVE-2019-3948
The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863

The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX V2.623.0000000.7.R, Dahua DH-SD5XXXXX V2.623.0000000.1.R, Dahua DH-SD6XXXXX V2.640.0000000.2.R and V2.623.0000000.1.R, Dahua NVR5XX-4KS2 V3.216.0000006.0.R, Dahua NVR4XXX-4KS2 V3.216.0000006.0.R, and NVR2XXX-4KS2 do not require authentication to access the HTTP endpoint /videotalk. An unauthenticated, remote person can connect to this endpoint and potentionally listen to the audio of the capturing device.

NVD description · AI analysis pending
7.525% PoC ×2
  • amcrest ip2m-841b firmware
  • amcrest dh-ipc-hx863x
  • amcrest dh-ipc-hx883x
  • +1 more
CVE-2017-8229
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials.

Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable function that sets up the default credentials on the device. If one opens this binary in IDA-pro one will notice that this follows a ARM little endian format. The function sub_436D6 in IDA pro is identified to be setting up the configuration for the device. If one scrolls to the address 0x000437C2 then one can see that /current_config is being set as an ALIAS for /mnt/mtd/Config folder on the device. If one TELNETs into the device and navigates to /mnt/mtd/Config folder, one can observe that it contains various files such as Account1, Account2, SHAACcount1, etc. This means that if one navigates to http://[IPofcamera]/current_config/Sha1Account1 then one should be able to view the content of the files. The security researchers assumed that this was only possible only after authentication to the device. However, when unauthenticated access tests were performed for the same URL as provided above, it was observed that the device file could be downloaded without any authentication.

NVD description · AI analysis pending
9.8
group max
74% PoC
  • amcrest ipm-721s firmware
CVE-2018-16546
Amcrest networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographi

Amcrest networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation, as demonstrated by Amcrest_IPC-HX1X3X-LEXUS_Eng_N_AMCREST_V2.420.AC01.3.R.20180206.

NVD description · AI analysis pending
5.91%
  • amcrest amcrest ipc-hx1x3x-lexus eng n amcrest
CVE-2016-10521
jshamcrest is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in to the emailAddress validator.

jshamcrest is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in to the emailAddress validator.

NVD description · AI analysis pending
7.51%
  • jshamcrest project jshamcrest