Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown

CVE-2018-17919

Disclosure Date: October 10, 2018 (last updated November 27, 2024)
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with its default password to login to XMeye and access/view video streams.
0
Attacker Value
Unknown

CVE-2018-17915

Disclosure Date: October 10, 2018 (last updated November 27, 2024)
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication. This includes the XMeye service and firmware update communication. This could allow an attacker to eavesdrop on video feeds, steal XMeye login credentials, or impersonate the update server with malicious update code.
0
Attacker Value
Unknown

CVE-2018-10088

Disclosure Date: June 08, 2018 (last updated November 26, 2024)
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.
0
Attacker Value
Unknown

CVE-2017-16725

Disclosure Date: December 20, 2017 (last updated November 26, 2024)
A Stack-based Buffer Overflow issue was discovered in Xiongmai Technology IP Cameras and DVRs using the NetSurveillance Web interface. The stack-based buffer overflow vulnerability has been identified, which may allow an attacker to execute code remotely or crash the device. After rebooting, the device restores itself to a more vulnerable state in which Telnet is accessible.
0
Attacker Value
Unknown

CVE-2017-7577

Disclosure Date: April 07, 2017 (last updated November 26, 2024)
XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request.
0