CVE-2025-52598

Severity CVSS v4.0:
MEDIUM
Type:
CWE-295 Improper Certificate Validation
Publication date:
26/12/2025
Last modified:
16/01/2026

Description

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has found a flaw that camera's client service does not perform certificate validation. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hanwhavision:xno-9082rz_firmware:*:*:*:*:*:*:*:* 2.24.00 (excluding)
cpe:2.3:h:hanwhavision:xno-9082rz:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwhavision:xnv-9082r_firmware:*:*:*:*:*:*:*:* 2.24.00 (excluding)
cpe:2.3:h:hanwhavision:xnv-9082r:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwhavision:xnd-9082rf_firmware:*:*:*:*:*:*:*:* 2.24.00 (excluding)
cpe:2.3:h:hanwhavision:xnd-9082rf:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwhavision:xnd-9082rv_firmware:*:*:*:*:*:*:*:* 2.24.00 (excluding)
cpe:2.3:h:hanwhavision:xnd-9082rv:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwhavision:xnb-9002_firmware:*:*:*:*:*:*:*:* 2.24.00 (excluding)
cpe:2.3:h:hanwhavision:xnb-9002:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwhavision:xnf-9010rv_firmware:*:*:*:*:*:*:*:* 2.24.00 (excluding)
cpe:2.3:h:hanwhavision:xnf-9010rv:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwhavision:xnf-9010rs_firmware:*:*:*:*:*:*:*:* 2.24.00 (excluding)
cpe:2.3:h:hanwhavision:xnf-9010rs:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwhavision:xnf-9010rvm_firmware:*:*:*:*:*:*:*:* 2.24.00 (excluding)