CVE-2020-9527

CRITICAL

Shenzhen Hichip Vision Technology Firmware - Buffer Overflow

Title source: rule
STIX 2.1

Description

Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20, after 2018-08-09 through 2020), as used by many different vendors in millions of Internet of Things devices, suffers from buffer overflow vulnerability that allows unauthenticated remote attackers to execute arbitrary code via the peer-to-peer (P2P) service. This affects products marketed under the following brand names: Accfly, Alptop, Anlink, Besdersec, BOAVISION, COOAU, CPVAN, Ctronics, D3D Security, Dericam, Elex System, Elite Security, ENSTER, ePGes, Escam, FLOUREON, GENBOLT, Hongjingtian (HJT), ICAMI, Iegeek, Jecurity, Jennov, KKMoon, LEFTEK, Loosafe, Luowice, Nesuniq, Nettoly, ProElite, QZT, Royallite, SDETER, SV3C, SY2L, Tenvis, ThinkValue, TOMLOV, TPTEK, WGCC, and ZILINK.

References (2)

Core 2
Core References
Not Applicable x_refsource_misc
https://hacked.camera/
Not Applicable x_refsource_misc
https://redprocyon.com

Scores

CVSS v3 9.8
EPSS 0.0758
EPSS Percentile 91.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (1)
hichip/shenzhen_hichip_vision_technology_firmware < 2020-06-29
Published Aug 10, 2020
Tracked Since Feb 18, 2026