ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-12223
An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before 2019-05-03.

An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before 2019-05-03. A system crash and reboot can be achieved by submitting a long username in excess of 117 characters. The username triggers a buffer overflow in the main process controlling operation of the DVR system, rendering services unavailable during the reboot operation. A repeated attack affects availability as long as the attacker has network access to the device.

NVD description · AI analysis pending
7.52% PoC
  • hanwha-security srn-472s firmware
  • hanwha-security srn-873s firmware
  • hanwha-security srn-1673s firmware
CVE-2018-11689
Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 paramete

Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)

NVD description · AI analysis pending
6.12% PoC ×3
  • samsung smartviewer
  • samsung hrd-1642 firmware
  • samsung hrd-842 firmware
  • +1 more
CVE-2018-6298
Remote code execution in Hanwha Techwin Smartcams

Remote code execution in Hanwha Techwin Smartcams

NVD description · AI analysis pending
9.8
group max
4%
  • hanwha-security snh-v6410pn firmware
  • hanwha-security snh-v6410pnw firmware
CVE-2017-5168
+1 in the same advisory: …5169
An issue was discovered in Hanwha Techwin Smart Security Manager Versions 1.5 and prior.

An issue was discovered in Hanwha Techwin Smart Security Manager Versions 1.5 and prior. Multiple Path Traversal vulnerabilities have been identified. The flaws exist within the ActiveMQ Broker service that is installed as part of the product. By issuing specific HTTP requests, if a user visits a malicious page, an attacker can gain access to arbitrary files on the server. Smart Security Manager Versions 1.4 and prior to 1.31 are affected by these vulnerabilities. These vulnerabilities can allow for remote code execution.

NVD description · AI analysis pending
7.54%
  • hanwha-security smart security manager