Critical severity9.8NVD Advisory· Published Oct 10, 2018· Updated Jun 17, 2026
CVE-2018-17915
CVE-2018-17915
Description
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication. This includes the XMeye service and firmware update communication. This could allow an attacker to eavesdrop on video feeds, steal XMeye login credentials, or impersonate the update server with malicious update code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:xiongmaitech:xmeye_p2p_cloud_server:-:*:*:*:*:*:*:*
all versions+ 1 more
- (no CPE)range: all versions
- (no CPE)range: All versions
Patches
Vulnerability mechanics
References
1- ics-cert.us-cert.gov/advisories/ICSA-18-282-06nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.