Junglewise Threat Intelligence

CVE-2024-54012: Hanwha Vision Camera OS command injection in KNB series firmware

CVE-2024-54012 · Severity: medium · CVSS 5.3 · Published 2026-04-28

Technologies: Hanwha Vision Knb-2000 Firmware, Hanwha Vision Knb-5000n Firmware.

Executive brief

A security vulnerability has been identified in certain Hanwha Vision camera systems that could allow an attacker to take control of the device. By sending specially crafted requests, an unauthorized party could execute malicious commands directly on the camera. This could lead to a complete loss of video privacy, service disruption, or the device being used as a foothold to attack other parts of the corporate network.

Technical details

An OS command injection vulnerability (CWE-78) exists in Hanwha Vision KNB-2000 and KNB-5000N camera firmware. The flaw stems from a failure to properly validate input in the camera system, which allows specially crafted requests containing malicious commands to be executed on the device. According to the vendor's CVSS 4.0 assessment, the attack vector is 'adjacent' (local network) and requires high privileges, though NVD's preliminary 3.1 assessment suggests a network vector. Successful exploitation grants the attacker full control over the device's operating system. The manufacturer has released firmware version 2.23.01 to address this issue.

Affected products

  • Hanwha Vision KNB-2000 firmware versions up to (excluding) 2.23.01
  • Hanwha Vision KNB-5000N firmware versions up to (excluding) 2.23.01

Timeline

  • 2026-04-28: disclosed: Vulnerability published on NVD
  • 2026-04-28: patched: Manufacturer released patch firmware version 2.23.01

References