ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-24217
+3 in the same advisory: …24214 …24215 …24216
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders.

An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly in conjunction with command injection, to achieve arbitrary code execution.

NVD description · AI analysis pending
9.8
group max
40% PoC ×3
  • szuray iptv\/h.264 video encoder firmware
  • szuray iptv\/h.265 video encoder firmware
  • szuray h.264 iptv encoder 1080p\@60hz firmware
  • +1 more