CVE-2020-9528

HIGH

Shenzhen Hichip Vision Technology Firmware < 2020-06-29 - Use of a Broken or Risky Cryptographic Algorithm

Title source: llm
STIX 2.1

Description

Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions of Internet of Things devices, suffers from cryptographic issues that allow remote attackers to access user session data, as demonstrated by eavesdropping on user video/audio streams, capturing credentials, and compromising devices. This affects products marketed under the following brand names: Accfly, Alptop, Anlink, Besdersec, BOAVISION, COOAU, CPVAN, Ctronics, D3D Security, Dericam, Elex System, Elite Security, ENSTER, ePGes, Escam, FLOUREON, GENBOLT, Hongjingtian (HJT), ICAMI, Iegeek, Jecurity, Jennov, KKMoon, LEFTEK, Loosafe, Luowice, Nesuniq, Nettoly, ProElite, QZT, Royallite, SDETER, SV3C, SY2L, Tenvis, ThinkValue, TOMLOV, TPTEK, WGCC, and ZILINK.

References (2)

Core 2
Core References
Not Applicable x_refsource_misc
https://hacked.camera/
Not Applicable x_refsource_misc
https://redprocyon.com

Scores

CVSS v3 7.5
EPSS 0.0083
EPSS Percentile 52.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-327
Status published
Products (1)
hichip/shenzhen_hichip_vision_technology_firmware < 2020-06-29
Published Aug 10, 2020
Tracked Since Feb 18, 2026