Home

Description

Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can cause a stack overflow by entering large data into URL parameters, which will result in a system reboot. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

PUBLISHED Reserved 2024-07-23 | Published 2024-12-24 | Updated 2025-10-01 | Assigner Hanwha_Vision




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-121 Stack-based Buffer Overflow

Product status

Default status
unaffected

5.01.62 and prior versions
affected

References

www.hanwhavision.com/...ility-Report-CVE-2024-4188241887.pdf vendor-advisory

cve.org (CVE-2024-41882)

nvd.nist.gov (CVE-2024-41882)

Download JSON