CVE-2018-11689
14.06.2018, 20:29
Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)
Vendor | Product | Version |
---|---|---|
samsung | smartviewer | - |
hanwha-security | hrd-1642_firmware | 𝑥 ≤ 1.16 |
hanwha-security | hrd-842_firmware | 𝑥 ≤ 1.16 |
hanwha-security | hrd-442_firmware | 𝑥 ≤ 1.16 |
hanwha-security | hrd-1641_firmware | 𝑥 ≤ 1.14 |
hanwha-security | hrd-841_firmware | 𝑥 ≤ 1.14 |
hanwha-security | hrd-840_firmware | 𝑥 ≤ 1.14 |
hanwha-security | hrd-440_firmware | 𝑥 ≤ 1.14 |
hanwha-security | hrd-443_firmware | 𝑥 ≤ 1.14 |
hanwha-security | srd-1694u_firmware | 𝑥 ≤ 1.14 |
𝑥
= Vulnerable software versions
References