CVE-2020-9529

CRITICAL

Shenzhen Hichip Vision Technology Firmware < 2020-06-29 - Privilege Escalation via Administrator Password Reset

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-9529. PoCs published by prisect.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2020-9529, which targets a vulnerability in Hichip IP cameras allowing an attacker to reset the admin password via a crafted UDP message. The exploit includes discovery and reset functionality, demonstrating the vulnerability effectively.

Description

Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions of Internet of Things devices, suffers from a privilege escalation vulnerability that allows attackers on the local network to reset the device's administrator password. This affects products marketed under the following brand names: Accfly, Alptop, Anlink, Besdersec, BOAVISION, COOAU, CPVAN, Ctronics, D3D Security, Dericam, Elex System, Elite Security, ENSTER, ePGes, Escam, FLOUREON, GENBOLT, Hongjingtian (HJT), ICAMI, Iegeek, Jecurity, Jennov, KKMoon, LEFTEK, Loosafe, Luowice, Nesuniq, Nettoly, ProElite, QZT, Royallite, SDETER, SV3C, SY2L, Tenvis, ThinkValue, TOMLOV, TPTEK, WGCC, and ZILINK.

Exploits (1)

nomisec WORKING POC
by prisect · poc
https://github.com/prisect/hichipreset

This repository contains a functional exploit for CVE-2020-9529, which targets a vulnerability in Hichip IP cameras allowing an attacker to reset the admin password via a crafted UDP message. The exploit includes discovery and reset functionality, demonstrating the vulnerability effectively.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Hichip IP Camera (specific version not specified)
No auth needed
Prerequisites: Network access to the target device · UDP port 12222 accessible
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Not Applicable x_refsource_misc
https://hacked.camera/
Not Applicable x_refsource_misc
https://redprocyon.com

Scores

CVSS v3 9.8
EPSS 0.0287
EPSS Percentile 85.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
hichip/shenzhen_hichip_vision_technology_firmware < 2020-06-29
Published Aug 10, 2020
Tracked Since Feb 18, 2026