Advisories

Analysis of specific vulnerabilities in video infrastructure: what is affected, what an attacker needs, whether it is being exploited, and what to do. Each advisory carries a revision history.

5 September 2026

A sudo bug is a camera bug: component vulnerabilities in video devices

CVE-2021-3156, the sudo heap overflow known as Baron Samedit, is recorded in NVD against the Synology VS960HD and has been in CISA's Known Exploited Vulnerabilities catalogue since April 2022. The catalogue files it under the vendor name "Sudo", so camera-vendor filters do not return it.

exploited
5 September 2026

Three exploited D-Link flaws filed under "NAS" that resolve to NVR hardware

Three D-Link flaws are in CISA's exploited catalogue: hard-coded credentials, a command injection, and a Backup Config integrity failure (CWE-494). The KEV entries read "NAS" and "DNR-322L"; the CPE match names DNR-series network video recorders.

exploited
5 September 2026

GeoVision end-of-life devices are being exploited and no patch is coming

Discontinued GeoVision IP cameras, video servers, LPR units and DVRs carry two unauthenticated OS command injection flaws that CISA records as exploited. The products are end-of-life, so there is no fix to apply and the remediation is removal.

exploited
5 September 2026

Hikvision web server command injection, and the older auth bypass in the same estate

An unauthenticated command injection in the Hikvision camera web server, alongside a 2017 improper-authentication flaw in an overlapping product line. CISA records both as exploited; 19 of 256 products carry version data.

exploited