Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can cause a stack overflow by entering large data into URL parameters, which will result in a system reboot. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.
Metrics
Affected Vendors & Products
References
History
Wed, 01 Oct 2025 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-119 |
Wed, 01 Oct 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-121 |
Tue, 24 Dec 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Dec 2024 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can cause a stack overflow by entering large data into URL parameters, which will result in a system reboot. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds. | |
| Title | Stack based buffer overflow | |
| Weaknesses | CWE-119 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Hanwha_Vision
Published: 2024-12-24T05:35:11.310Z
Updated: 2025-10-01T01:55:06.444Z
Reserved: 2024-07-23T00:24:03.860Z
Link: CVE-2024-41882
Updated: 2024-12-24T15:23:16.583Z
Status : Awaiting Analysis
Published: 2024-12-24T06:15:33.810
Modified: 2025-10-01T03:15:36.457
Link: CVE-2024-41882
No data.