Junglewise Threat Intelligence

CVE-2026-32683: EZVIZ APP Cleartext Transmission of Sensitive Information in Cloud Modules

CVE-2026-32683 · Severity: medium · CVSS 5.3 · Published 2026-05-09

Executive brief

Certain EZVIZ smart home products use outdated cloud communication modules that do not properly secure data during transmission. An attacker on the same local network could potentially intercept network traffic to eavesdrop on sensitive information, including video data. To mitigate this risk, users must update their mobile application and manually enable the video encryption feature within the app settings.

Technical details

The vulnerability (CWE-319) exists in the cloud feature modules of the EZVIZ mobile application due to the use of legacy API interfaces that transmit data without sufficient encryption. An attacker with adjacent network access (e.g., on the same Wi-Fi network) can perform network eavesdropping to intercept sensitive data transmissions. Exploitation requires a high degree of complexity as the attacker must be positioned to capture the specific traffic. The issue is resolved in iOS version 7.3.1 and Android version 7.3.0.0210; however, users must also ensure the 'video encryption' feature is enabled to fully protect the data stream.

Affected products

  • EZVIZ EZVIZ APP (iOS) Prior to 7.3.1
  • EZVIZ EZVIZ APP (Android) Prior to 7.3.0.0210

Timeline

  • 2026-05-08: advisory: Initial release of security notice by EZVIZ
  • 2026-05-09: disclosed: CVE published to NVD

References