cbcvebase.

Hanwhavision Qnp-6250 Firmware vulnerabilities

10 known vulnerabilities affecting hanwhavision/qnp-6250_firmware.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM5LOW1

Vulnerabilities

Page 1 of 1
CVE-2023-31996P3HIGHCVSS 8.8fixed in 1.41.142023-05-23
CVE-2023-31996 [HIGH] CWE-77 CVE-2023-31996: Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Command Injection due to improper sanitization Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Command Injection due to improper sanitization of special characters for the NAS storage test function.
nvd
CVE-2024-54013P3HIGHCVSS 8.8fixed in 2.23.012026-04-28
CVE-2024-54013 [HIGH] CWE-306 CVE-2024-54013: Penetration Testing engineers at Amazon have identified a security flaw related to request handling Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server component that could, under certain conditions, lead to unintended access to protected functions. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds
nvd
CVE-2025-52600P3HIGHCVSS 7.2fixed in 2.23.012025-12-26
CVE-2025-52600 [HIGH] CWE-20 CVE-2025-52600: Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Sys Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a vulnerability in camera video analytics that Improper input validation. This vulnerability could allow an attacker to execute specific commands on the user's host PC.The manufacturer has released patch fir
nvd
CVE-2025-52601P3HIGHCVSS 7.8fixed in 2.23.012025-12-26
CVE-2025-52601 [HIGH] CWE-321 CVE-2025-52601: Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Sys Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a vulnerability in Device Manager that a hardcoded encryption key for sensitive information. An attacker can use key to decrypt sensitive information. The manufacturer has released patch firmware for the fl
nvd
CVE-2025-52599P3MEDIUMCVSS 6.5fixed in 2.23.012025-12-26
CVE-2025-52599 [MEDIUM] CWE-269 CVE-2025-52599: Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Sys Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered Inadequate of permission management for camera guest account. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.
nvd
CVE-2024-54011P4MEDIUMCVSS 6.5fixed in 2.23.012026-04-28
CVE-2024-54011 [MEDIUM] CWE-20 CVE-2024-54011: Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to prop Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to properly handle data supplied in certain requests, causing a service disruption. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.
nvd
CVE-2024-54012P4MEDIUMCVSS 5.3fixed in 2.23.012026-04-28
CVE-2024-54012 [MEDIUM] CWE-78 CVE-2024-54012: Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially crafted requests containing malicious commands to be executed on the device. The manufacturer has released patch firmware for the flaw; please refer to the manufacturer's report for details and workarounds.
nvd
CVE-2025-8075P4MEDIUMCVSS 5.4fixed in 2.23.012025-12-26
CVE-2025-8075 [MEDIUM] CWE-20 CVE-2025-8075: Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Sys Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered that validation of incoming XML format request messages is inadequate. This vulnerability could allow an attacker to XSS on the user's browser. The manufacturer has released patch firmware for the flaw, plea
nvd
CVE-2023-31995P4MEDIUMCVSS 5.4fixed in 1.41.142023-05-23
CVE-2023-31995 [MEDIUM] CWE-79 CVE-2023-31995: Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Cross Site Scripting (XSS). Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Cross Site Scripting (XSS).
nvd
CVE-2025-52598P4LOWCVSS 3.7fixed in 2.23.012025-12-26
CVE-2025-52598 [LOW] CWE-295 CVE-2025-52598: Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Sys Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has found a flaw that camera's client service does not perform certificate validation. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.
nvd
Hanwhavision Qnp-6250 Firmware vulnerabilities | cvebase