« Back to list

Amcrest

Amcrest Ip2m-866ew Firmware: vulnerabilities and CVEs

Amcrest Ip2m-866ew Firmware has 2 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 1 are listed by CISA as actively exploited.

CVEs2
Last 12 months0
Critical0
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2020-5735High (8.8)36%⚠ Active exploitationApr 8, 2020
Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2020-5736Medium (6.5)1.6%—Apr 8, 2020
Amcrest cameras and NVR are vulnerable to a null pointer dereference over port 37777. An authenticated remote attacker can abuse this issue to crash the device.
CVE-2020-5735High (8.8)36%⚠ Active exploitationApr 8, 2020
Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Amcrest