CVE-2024-54012
published 2026-04-28CVE-2024-54012: Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially crafted…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.26%
17.0th percentile
Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially crafted requests containing malicious commands to be executed on the device. The manufacturer has released patch firmware for the flaw; please refer to the manufacturer's report for details and workarounds.
Affected
254 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hanwha_vision | qnd-8080r | < 2.24.00 | 2.24.00 |
| hanwhavision | knb-2000_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | knb-5000n_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | knd-2010_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | knd-2020rn_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | knd-2080rn_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | knd-5020rn_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | knd-5080rn_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | kno-2010rn_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | kno-2080rn_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | kno-2120rn_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | kno-5020rn_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | kno-5080rn_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | knp-2120hn_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | knp-2320rh_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | knp-2320rha_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | knp-2550rha_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | pnd-a6081rv_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | pnd-a9081rv_firmware | < 2.23.01 | 2.23.01 |
| hanwhavision | pnm-7000vd_firmware | < 2.23.00 | 2.23.00 |
| hanwhavision | pnm-7002vd_firmware | < 2.23.00 | 2.23.00 |
| hanwhavision | pnm-9000vd_firmware | < 2.23.00 | 2.23.00 |
| hanwhavision | pnm-9000vq_firmware | < 2.23.00 | 2.23.00 |
| hanwhavision | pnm-9002vq_firmware | < 2.23.00 | 2.23.00 |
| hanwhavision | pnm-9080vq_firmware | < 2.23.00 | 2.23.00 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv4.08.5HIGHCVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-94qr-xmg5-q7cw: Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially craft
ghsa_unreviewed·2026-04-28
CVE-2024-54012 [HIGH] CWE-78 GHSA-94qr-xmg5-q7cw: Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially craft
Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially crafted requests containing malicious commands to be executed on the device. The manufacturer has released patch firmware for the flaw; please refer to the manufacturer's report for details and workarounds.
VulDB
Hanwha Vision QND-8080R up to 2.23.x Request os command injection (EUVD-2024-55559)
vuldb·2026-04-28·CVSS 8.5
CVE-2024-54012 [HIGH] Hanwha Vision QND-8080R up to 2.23.x Request os command injection (EUVD-2024-55559)
A vulnerability was found in Hanwha Vision QND-8080R up to 2.23.x. It has been declared as critical. Affected by this issue is some unknown functionality of the component Request Handler. Executing a manipulation can lead to os command injection.
This vulnerability is tracked as CVE-2024-54012. The attack is only possible within the local network. No exploit exists.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-28
Published