Advisories
Analysis of specific vulnerabilities in video infrastructure: what is affected, what an attacker needs, whether it is being exploited, and what to do. Each advisory carries a revision history.
A sudo bug is a camera bug: component vulnerabilities in video devices
CVE-2021-3156, the sudo heap overflow known as Baron Samedit, is recorded in NVD against the Synology VS960HD and has been in CISA's Known Exploited Vulnerabilities catalogue since April 2022 — catalogued under the vendor name "Sudo", where no camera owner is looking.
Three exploited D-Link flaws filed under "NAS" that resolve to NVR hardware
Two D-Link command-injection and hard-coded-credential flaws plus a Backup Config integrity failure (CWE-494) are in CISA's exploited catalogue; the KEV entries say "NAS" and "DNR-322L", but the CPE match names DNR-series network video recorders.
GeoVision end-of-life devices are being exploited and no patch is coming
Discontinued GeoVision IP cameras, video servers, LPR units and DVRs carry two unauthenticated OS command injection flaws that CISA records as exploited, and because the products are end-of-life there is no fix to apply.
Hikvision web server command injection, and the older auth bypass in the same estate
An unauthenticated command injection in the Hikvision camera web server, alongside a 2017 improper-authentication flaw in an overlapping product line; both are recorded by CISA as exploited.