Junglewise Threat Intelligence

CVE-2024-54011: Hanwha Vision Camera improper input validation in firmware

CVE-2024-54011 · Severity: medium · CVSS 6.5 · Published 2026-04-28

Technologies: Hanwha Vision Knb-5000n Firmware, Hanwha Vision Knb-2000 Firmware.

Executive brief

A vulnerability has been identified in certain Hanwha Vision camera systems that can lead to a service disruption. An attacker can send specially crafted data to the camera, causing it to stop functioning correctly. This could impact physical security monitoring and operational uptime until the system is recovered.

Technical details

An improper input validation vulnerability (CWE-20) exists in Hanwha Vision KNB-2000 and KNB-5000N camera firmware. The system fails to properly handle data supplied in specific network requests, which can be exploited to cause a denial-of-service (DoS) condition. Exploitation requires network reachability and low-level user privileges (PR:L). The vulnerability was discovered by Amazon penetration testing engineers and is addressed in firmware version 2.23.01 and later.

Affected products

  • Hanwha Vision KNB-2000 Firmware before 2.23.01
  • Hanwha Vision KNB-5000N Firmware before 2.23.01

Timeline

  • 2026-04-28: advisory: Initial disclosure date
  • 2026-04-28: patched: Firmware version 2.23.01 released to address the flaw

References