Hanwha Vision Camera Vulnerability Report and Firmware Updates

Hanwha Vision

6, Pangyo-ro 319beon-gil, Bundang-gu, Seongnam-si, Gyeonggi-do, 13488, Korea

TEL 82.70.7147.7000 FAX 82.31.8018.3702 www.HanwhaVision.com

2023 Hanwha Vision S-Cert Team

Date: 4/26/2023 (Updated: 5/9/2023)

Camera Vulnerability Report

OVERVIEW

IPVM (Bashis) identified three vulnerabilities in Hanwha cameras and reported them to Hanwha S-CERT on February 7th, 2023.

Vulnerability Description
Authenticated Command Injection Randomly injecting a command into the folder mount point of the NAS function and executing a Linux command.
DoS of WS Discovery and Hanwha proprietary discovery services After injecting EMPTY packets into the 3702 / 7701 ports used for device discovery of ONVIF/Device Manager, the discovery function can be disabled.
Authenticated XSS Can be executed by injecting the script into the imageData/backupfileData parameters of /home/setup/imagedownload.cgi.

AFFECTED PRODUCTS AND FIRMWARE

These vulnerabilities affect the following series models. Please refer to the tables below for affected series, affected firmware versions, and corrected firmware versions.

Model Affected Firmware Version Corrected Firmware Version
A Series 1.41.02 and earlier versions 1.41.03 and later versions
Q Series (Basic 2M) 1.41.13 and earlier versions 1.41.14 and later versions
Q Series (Others) 1.41.04 and earlier versions 1.41.05 and later versions
PNM Series 1.33.03 and earlier versions / 2.21.01 and earlier versions 2.22.00 and later versions

RISK ANALYSIS

Vulnerability Review Opinion Severity
Authenticated Command Injection Hanwha was filtering special characters in the DefaultFolder factor used for the NAS function, but it was confirmed that the command could be executed due to the missing special character '$'. However, this vulnerability requires authentication before it can be executed. Middle
DoS of WS Discovery and Hanwha proprietary discovery services

Even if a DoS attack occurs, service limitations occur only in the discovery function to find products on the local network, not in all services of Hanwha Products.

RISK MITIGATION: In situations where there is a DoS attack and the firmware cannot be updated, rebooting the device can temporarily solve the problem.

※ Only, this vulnerability affects all Hanwha products. So, all Hanwha products have been released with corrected firmware. (Refer to Section A)

Low
Authenticated XSS It is difficult to exploit because it is very difficult to run on the actual browser. Also, even if JavaScript is executed, no additional benefits are obtained. This vulnerability requires authentication as well before it can be exploited. Low

Current Status and Required Action

Regardless of the severity of the vulnerabilities discovered, Hanwha Vision has resolved these vulnerabilities by releasing corrected firmware.

Please update affected models with the latest firmware. It is recommended to use the Wisenet Device Manager tool to download & update device firmware. Firmware can also be downloaded from the Hanwha Vision website.

If you have any questions, please feel free to reach out to the Hanwha S-CERT team at secure.cctv@hanwha.com or your local Technical Support Team.

A. Release Plan for DoS of WS Discovery and Hanwha proprietary discovery services

Model Affected Firmware Version Corrected Firmware Version
P Series 2.11.03 and earlier versions 2.12.00 and later versions
X Series 2.21.00 and earlier versions 2.22.00 and later versions
T Series 2.11.11 and earlier versions 2.12.00 and later versions
L Series 1.41.11 and earlier versions 1.41.12 and later versions
Encoder 2.11.03 and earlier versions 2.21.01 and later versions

PDF preview unavailable. Download the PDF instead.

Camera-Vulnerability-Report 20230509 Microsoft Word 2016 Microsoft Word 2016

Related Documents

Preview Hanwha Vision Firmware Decryption Key Disclosure Statement
Official statement from Hanwha Vision Cybersecurity Team regarding firmware decryption key disclosure, outlining affected camera models, risks, and mitigation measures.
Preview Hanwha Vision 2025 2H Product Portfolio: Advanced Video Surveillance Solutions
Explore the comprehensive 2025 2H Product Portfolio from Hanwha Vision, featuring cutting-edge AI cameras, PTZ, thermal, and fisheye solutions, alongside NVRs and access control systems for advanced video security.
Preview Hanwha Vision AI Cameras, NVRs, and Video Security Solutions Product Portfolio
Comprehensive product catalog from Hanwha Vision, detailing AI cameras, Network Video Recorders (NVRs), and video security peripherals. Features include advanced analytics, cybersecurity, and detailed technical specifications for various models.
Preview Hanwha Vision 2023 Product Portfolio: Advanced Security Solutions
Explore the comprehensive 2023 product portfolio from Hanwha Vision, featuring advanced AI cameras, NVRs, and security solutions designed for superior surveillance and intelligent insights.
Preview Hanwha Vision Firmware Encryption Key Disclosure Statement
Official statement from Hanwha Vision regarding the disclosure of an encryption key in certain camera firmware, outlining the affected models, risks, and mitigation strategies.
Preview Hanwha Vision WiseDetector: Custom Object Detection for AI Cameras
Learn about Hanwha Vision's WiseDetector, a machine learning model that allows users to train AI cameras to detect specific, user-defined objects. This brochure details the setup, training process, and compatible P-series cameras.
Preview Hanwha Vision XNO-A9084R 8MP AI IR Bullet Kamera Teknik Özellikleri
Hanwha Vision XNO-A9084R 8MP AI IR Bullet Kamera'nın temel özelliklerini, AI destekli analiz yeteneklerini, teknik detaylarını ve dayanıklılık sertifikalarını keşfedin. Detaylı güvenlik çözümleri için.
Preview Hanwha Vision XNV-A9084R : Caméra Dôme IR Anti-vandale 8 Mpx - Spécifications Techniques
Découvrez la caméra dôme IR anti-vandale 8 Mpx Hanwha Vision XNV-A9084R. Spécifications techniques complètes incluant objectif varifocal motorisé, analyse vidéo IA, WDR, WiseIR 40m, et certifications IP66/IP67/IK10.