CVE-2026-32683

medium

Description

Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmission risk. Attackers can exploit this by eavesdropping on network requests to obtain data.Users are advised to upgrade the app to the latest version and enable the video encryption feature.

References

https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-cloud-function-modules-of-some-hikvisi/

https://www.ezviz.com/inter/trust-center/security/security-notice/2026.05.08

Details

Source: Mitre, NVD

Published: 2026-05-09

Updated: 2026-05-09

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:A/AC:H/Au:N/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: Medium