<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>VideoSOC — advisories and analysis</title>
  <subtitle>Vulnerabilities, exploitation and vendor advisories affecting video infrastructure</subtitle>
  <link href="https://videosoc.com/feed.xml" rel="self"/>
  <link href="https://videosoc.com/"/>
  <id>https://videosoc.com/</id>
  <updated>2026-09-05T00:00:00Z</updated>
  <entry>
    <title>A sudo bug is a camera bug: component vulnerabilities in video devices</title>
    <link href="https://videosoc.com/advisories/component-vulnerabilities-in-video-devices/"/>
    <id>https://videosoc.com/advisories/component-vulnerabilities-in-video-devices/</id>
    <updated>2026-09-05T00:00:00Z</updated>
    <published>2026-09-05T00:00:00Z</published>
    <summary>CVE-2021-3156, the sudo heap overflow known as Baron Samedit, is recorded in NVD against the Synology VS960HD and has been in CISA&#39;s Known Exploited Vulnerabilities catalogue since April 2022 — catalogued under the vendor name &quot;Sudo&quot;, where no camera owner is looking.</summary>
  </entry>
  <entry>
    <title>Three exploited D-Link flaws filed under &quot;NAS&quot; that resolve to NVR hardware</title>
    <link href="https://videosoc.com/advisories/dlink-network-storage-and-nvr-exploited/"/>
    <id>https://videosoc.com/advisories/dlink-network-storage-and-nvr-exploited/</id>
    <updated>2026-09-05T00:00:00Z</updated>
    <published>2026-09-05T00:00:00Z</published>
    <summary>Two D-Link command-injection and hard-coded-credential flaws plus a Backup Config integrity failure (CWE-494) are in CISA&#39;s exploited catalogue; the KEV entries say &quot;NAS&quot; and &quot;DNR-322L&quot;, but the CPE match names DNR-series network video recorders.</summary>
  </entry>
  <entry>
    <title>GeoVision end-of-life devices are being exploited and no patch is coming</title>
    <link href="https://videosoc.com/advisories/geovision-end-of-life-devices-exploited/"/>
    <id>https://videosoc.com/advisories/geovision-end-of-life-devices-exploited/</id>
    <updated>2026-09-05T00:00:00Z</updated>
    <published>2026-09-05T00:00:00Z</published>
    <summary>Discontinued GeoVision IP cameras, video servers, LPR units and DVRs carry two unauthenticated OS command injection flaws that CISA records as exploited, and because the products are end-of-life there is no fix to apply.</summary>
  </entry>
  <entry>
    <title>Hikvision web server command injection, and the older auth bypass in the same estate</title>
    <link href="https://videosoc.com/advisories/hikvision-web-server-command-injection/"/>
    <id>https://videosoc.com/advisories/hikvision-web-server-command-injection/</id>
    <updated>2026-09-05T00:00:00Z</updated>
    <published>2026-09-05T00:00:00Z</published>
    <summary>An unauthenticated command injection in the Hikvision camera web server, alongside a 2017 improper-authentication flaw in an overlapping product line; both are recorded by CISA as exploited.</summary>
  </entry>
</feed>
