Remote Code Execution Vulnerability in Hanwha Techwin NVR Products
CVE-2024-41886

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
24 December 2024

What is CVE-2024-41886?

A recently identified security vulnerability in Hanwha Techwin's Network Video Recorders exposes systems to potential remote code execution. Security researchers from Team ENVY have revealed that attackers can exploit this flaw by injecting malformed data into URL input parameters, leading to unintended system reboots. Affected users are encouraged to review the manufacturer’s advisory for guidance on applying the released firmware patches and implementing additional security measures to safeguard their devices.

Affected Version(s)

XRN-420S 5.01.62 and prior versions

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-41886 : Remote Code Execution Vulnerability in Hanwha Techwin NVR Products