CVE-2023-5037
Severity CVSS v4.0:
HIGH
Type:
CWE-78
OS Command Injections
Publication date:
13/11/2023
Last modified:
21/11/2024
Description
badmonkey, a Security Researcher has found a flaw that allows for a authenticated command injection on the camera. An attacker could inject malicious into request packets to execute command. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:hanwhavision:ano-l6012r_firmware:*:*:*:*:*:*:*:* | 1.41.16 (excluding) | |
| cpe:2.3:h:hanwhavision:ano-l6012r:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hanwhavision:ano-l6022r_firmware:*:*:*:*:*:*:*:* | 1.41.16 (excluding) | |
| cpe:2.3:h:hanwhavision:ano-l6022r:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hanwhavision:anv-l6012r_firmware:*:*:*:*:*:*:*:* | 1.41.16 (excluding) | |
| cpe:2.3:h:hanwhavision:anv-l6012r:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hanwhavision:ano-l6082r_firmware:*:*:*:*:*:*:*:* | 1.41.16 (excluding) | |
| cpe:2.3:h:hanwhavision:ano-l6082r:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hanwhavision:ane-l6012r_firmware:*:*:*:*:*:*:*:* | 1.41.16 (excluding) | |
| cpe:2.3:h:hanwhavision:ane-l6012r:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hanwhavision:anv-l6082r_firmware:*:*:*:*:*:*:*:* | 1.41.16 (excluding) | |
| cpe:2.3:h:hanwhavision:anv-l6082r:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hanwhavision:ano-l7082r_firmware:*:*:*:*:*:*:*:* | 1.41.16 (excluding) | |
| cpe:2.3:h:hanwhavision:ano-l7082r:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hanwhavision:ane-l7012r_firmware:*:*:*:*:*:*:*:* | 1.41.16 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



