Description
Buffer overflow in the RTSP Packet Handler in Hikvision DS-2CD7153-E IP camera with firmware 4.1.0 b130111 (Jan 2013), and possibly other devices, allows remote attackers to cause a denial of service (device crash and reboot) and possibly execute arbitrary code via a long string in the Range header field in an RTSP transaction.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Core Security · textwebappshardware
https://www.exploit-db.com/exploits/27402
References (5)
Core 5
Core References
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/61642
Exploit x_refsource_misc
http://www.coresecurity.com/advisories/hikvision-ip-cameras-multiple-vulnerabilities
Third Party Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2013-08/0046.html
Exploit, Third Party Advisory x_refsource_misc
http://packetstormsecurity.com/files/122718/Hikvision-IP-Cameras-Overflow-Bypass-Privilege-Escalation.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/86292
Scores
EPSS
0.5021
EPSS Percentile
97.9%
Details
CWE
CWE-119
Status
published
Products (2)
hikvision/ds-2cd7153-e
hikvision/ds-2cd7153-e_firmware
4.1.0_b130111
Published
Mar 03, 2014
Tracked Since
Feb 18, 2026