CVE-2017-14262

HIGH

Samsung SRN-1670D, SRN-1000, SRN-472S, SRN-470D Firmware - Unauthenticated Admin Password Hash Exposure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-14262. PoCs published by zzz66686.

AI-analyzed exploit summary This PoC demonstrates an authentication bypass vulnerability in Samsung NVR devices by retrieving the MD5 hash of the admin password via an unauthenticated API call and then using it to log in. The exploit leverages weak access controls to expose sensitive credentials.

Description

On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUserPasswd parameter.

Exploits (1)

nomisec WORKING POC 6 stars
by zzz66686 · poc
https://github.com/zzz66686/CVE-2017-14262

This PoC demonstrates an authentication bypass vulnerability in Samsung NVR devices by retrieving the MD5 hash of the admin password via an unauthenticated API call and then using it to log in. The exploit leverages weak access controls to expose sensitive credentials.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Samsung NVR devices (version not specified)
No auth needed
Prerequisites: Network access to the target device · Target device must be running vulnerable firmware
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://github.com/zzz66686/Samsung_NVR_vul

Scores

CVSS v3 8.1
EPSS 0.2102
EPSS Percentile 95.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-326
Status published
Products (4)
samsung/srn_1000_firmware
samsung/srn_1670d_firmware
samsung/srn_470d_firmware
samsung/srn_472s_firmware
Published Sep 11, 2017
Tracked Since Feb 18, 2026