VYPR
Vendor

Hisilicon

Products
5
CVEs
10
Across products
14
Status
Private

Products

5

Recent CVEs

10
  • CVE-2020-24217CriOct 6, 2020
    risk 0.70cvss 9.8epss 0.40

    An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly in conjunction with…

  • CVE-2020-24214CriOct 6, 2020
    risk 0.70cvss 9.8epss 0.35

    An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a crafted unauthenticated RTSP request to cause a buffer overflow and application crash. The device will not be able to perform its main purpose of video…

  • CVE-2020-24215CriOct 6, 2020
    risk 0.68cvss 9.8epss 0.20

    An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the device including retrieving the device's configuration (with the cleartext admin…

  • CVE-2019-11560CriMay 7, 2019
    risk 0.64cvss 9.8epss 0.02

    A buffer overflow vulnerability in the streaming server provided by hisilicon in HI3516 models allows an unauthenticated attacker to remotely run arbitrary code by sending a special RTSP over HTTP packet. The vulnerability was found in many cameras using hisilicon's hardware and…

  • CVE-2019-10710HigApr 23, 2019
    risk 0.57cvss 8.8epss 0.01

    Insecure permissions in the Web management portal on all IP cameras based on Hisilicon Hi3510 firmware allow authenticated attackers to receive a network's cleartext WiFi credentials via a specific HTTP request. This affects certain devices labeled as HI3510, HI3518, LOOSAFE,…

  • CVE-2019-25465HigMar 11, 2026
    risk 0.49cvss 7.5epss 0.01

    Hisilicon HiIpcam V100R003 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by exploiting directory listing in the cgi-bin directory. Attackers can request the getadslattr.cgi endpoint to retrieve ADSL…

  • CVE-2020-24216HigOct 6, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. When the administrator configures a secret URL for RTSP streaming, the stream is still available via its default name such as /0. Unauthenticated attackers can view video streams…

  • CVE-2019-10711HigApr 23, 2019
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the RTSP stream and web portal on all IP cameras based on Hisilicon Hi3510 firmware (until Webware version V1.0.1) allows attackers to view an RTSP stream by connecting to the stream with hidden credentials (guest or user) that are neither displayed…

  • CVE-2026-41516LowJul 6, 2026
    risk 0.00cvss 2.5epss 0.00

    OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.5.0 and prior to version 4.11.0, the RSA PKCS#1 v1.5 decryption implementation in the Hisilicon…

  • CVE-2026-41514LowJul 6, 2026
    risk 0.00cvss 2.5epss 0.00

    OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.5.0 and prior to version 4.11.0, the RSA-OAEP decryption implementation in the Hisilicon HPRE…