Hanwha Vision
[Statement] Firmware decryption key disclosure
06.13.2025
Hanwha Vision Cybersecurity Team (S-Cert)
Hanwha Vision has become aware of a recently published blog post and videos analyzing the security of a specific Hanwha Vision camera product. Following an internal investigation by Hanwha Vision Cybersecurity Team (S-CERT), it has been confirmed that the issue is limited to the following camera models:
- Wisenet 5 based X/T series, Wisenet Q series, Wisenet A series, and older PNM Multi-sensor cameras
Hanwha Vision would like to assure its customers that, to date, there have been no reported security breaches or serious data leaks involving these camera products. Below is a summary of the analysis of the video/blog content, the associated risks, and the mitigation approach.
Summary of the Published Blog/Video Content
- Analysis of camera firmware using sophisticated and destructive "chip-off + flash memory dump" techniques. The analysis was not performed with the device on a network.
- Exposure of the encryption keys within the firmware.
Risk Assessment
- For certain older camera models identified in the videos, it might be possible to modify firmware with a malicious intent. However, all Hanwha Vision network devices are protected by password-based access control, and modified firmware cannot be installed in the devices without device credentials.
- This issue is a known and common risk affecting many conventional IoT devices that do not support secure update or secure boot features.
Risk Mitigation Measures
- Use only firmware distributed through Hanwha Vision's official websites¹ or Wisenet Device Manager Software provided from Hanwha Vision.
- Apply the latest firmware updates to prevent the installation of unauthorized firmware.
- Ensure strong password management for all device administrator passwords.
Enhanced Security Measures
For affected legacy camera models, Hanwha Vision is updating the exposed encryption keys and implementing firmware digital signature verification, with which the cameras will reject unauthorized firmware files.
Please note that this issue does not affect Hanwha Vision's latest camera models, which already feature digital signature verification.
Hanwha Vision remains committed to resolving any and all product security concerns and to safeguarding the trust of its customers. Firmware patches and additional updates will be distributed exclusively through Hanwha Vision's official websites. Users are strongly encouraged to download and apply the latest firmware only available on Hanwha Vision's official websites.