Remote Code Execution Vulnerability in Hanwha Techwin NVR Products
CVE-2024-41882

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
24 December 2024

What is CVE-2024-41882?

A newly discovered vulnerability in Hanwha Techwin NVR products enables attackers to execute remote code by exploiting a stack overflow caused by oversized data inputs in URL parameters. By manipulating these inputs, an attacker can trigger a system reboot and potentially gain control of the affected device. The manufacturer has responded by releasing updated firmware to address this security issue. Users are encouraged to review the manufacturer's report for detailed patch information and additional workarounds to safeguard their systems.

Affected Version(s)

XRN-420S 5.01.62 and prior versions

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-41882 : Remote Code Execution Vulnerability in Hanwha Techwin NVR Products