Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)
2018-06-14T20:29:00.317
2024-11-21T03:43:49.723
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | samsung | smartviewer | - | Yes |
| Operating System | hanwha-security | hrd-1642_firmware | ≤ 1.16 | Yes |
| Hardware | hanwha-security | hrd-1642 | - | No |
| Operating System | hanwha-security | hrd-842_firmware | ≤ 1.16 | Yes |
| Hardware | hanwha-security | hrd-842 | - | No |
| Operating System | hanwha-security | hrd-442_firmware | ≤ 1.16 | Yes |
| Hardware | hanwha-security | hrd-442 | - | No |
| Operating System | hanwha-security | hrd-1641_firmware | ≤ 1.14 | Yes |
| Hardware | hanwha-security | hrd-1641 | - | No |
| Operating System | hanwha-security | hrd-841_firmware | ≤ 1.14 | Yes |
| Hardware | hanwha-security | hrd-841 | - | No |
| Operating System | hanwha-security | hrd-840_firmware | ≤ 1.14 | Yes |
| Hardware | hanwha-security | hrd-840 | - | No |
| Operating System | hanwha-security | hrd-440_firmware | ≤ 1.14 | Yes |
| Hardware | hanwha-security | hrd-440 | - | No |
| Operating System | hanwha-security | hrd-443_firmware | ≤ 1.14 | Yes |
| Hardware | hanwha-security | hrd-443 | - | No |
| Operating System | hanwha-security | srd-1694u_firmware | ≤ 1.14 | Yes |
| Hardware | hanwha-security | srd-1694u | - | No |