<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>VideoSOC — advisories and analysis</title>
  <subtitle>Vulnerabilities, exploitation and vendor advisories affecting video infrastructure</subtitle>
  <link href="https://videosoc.com/feed.xml" rel="self"/>
  <link href="https://videosoc.com/"/>
  <id>https://videosoc.com/</id>
  <updated>2026-09-05T00:00:00Z</updated>
  <entry>
    <title>A sudo bug is a camera bug: component vulnerabilities in video devices</title>
    <link href="https://videosoc.com/advisories/component-vulnerabilities-in-video-devices/"/>
    <id>https://videosoc.com/advisories/component-vulnerabilities-in-video-devices/</id>
    <updated>2026-09-05T00:00:00Z</updated>
    <published>2026-09-05T00:00:00Z</published>
    <summary>CVE-2021-3156, the sudo heap overflow known as Baron Samedit, is recorded in NVD against the Synology VS960HD and has been in CISA&#39;s Known Exploited Vulnerabilities catalogue since April 2022. The catalogue files it under the vendor name &quot;Sudo&quot;, so camera-vendor filters do not return it.</summary>
  </entry>
  <entry>
    <title>Three exploited D-Link flaws filed under &quot;NAS&quot; that resolve to NVR hardware</title>
    <link href="https://videosoc.com/advisories/dlink-network-storage-and-nvr-exploited/"/>
    <id>https://videosoc.com/advisories/dlink-network-storage-and-nvr-exploited/</id>
    <updated>2026-09-05T00:00:00Z</updated>
    <published>2026-09-05T00:00:00Z</published>
    <summary>Three D-Link flaws are in CISA&#39;s exploited catalogue: hard-coded credentials, a command injection, and a Backup Config integrity failure (CWE-494). The KEV entries read &quot;NAS&quot; and &quot;DNR-322L&quot;; the CPE match names DNR-series network video recorders.</summary>
  </entry>
  <entry>
    <title>GeoVision end-of-life devices are being exploited and no patch is coming</title>
    <link href="https://videosoc.com/advisories/geovision-end-of-life-devices-exploited/"/>
    <id>https://videosoc.com/advisories/geovision-end-of-life-devices-exploited/</id>
    <updated>2026-09-05T00:00:00Z</updated>
    <published>2026-09-05T00:00:00Z</published>
    <summary>Discontinued GeoVision IP cameras, video servers, LPR units and DVRs carry two unauthenticated OS command injection flaws that CISA records as exploited. The products are end-of-life, so there is no fix to apply and the remediation is removal.</summary>
  </entry>
  <entry>
    <title>Hikvision web server command injection, and the older auth bypass in the same estate</title>
    <link href="https://videosoc.com/advisories/hikvision-web-server-command-injection/"/>
    <id>https://videosoc.com/advisories/hikvision-web-server-command-injection/</id>
    <updated>2026-09-05T00:00:00Z</updated>
    <published>2026-09-05T00:00:00Z</published>
    <summary>An unauthenticated command injection in the Hikvision camera web server, alongside a 2017 improper-authentication flaw in an overlapping product line. CISA records both as exploited; 19 of 256 products carry version data.</summary>
  </entry>
</feed>
