Uniview IP Cameras Classic Buffer Overflow (CVE-2021-45039)

critical Tenable OT Security Plugin ID 506028

Synopsis

The remote OT asset is affected by a vulnerability.

Description

Multiple models of the Uniview IP Camera offer an undocumented UDP service on port 7788 that allows a remote, unauthenticated attacker to overflow an internal buffer and achieve code execution.

By using this buffer overflow, a remote attacker can start the telnetd service. This service has a hardcoded default username and password.
Although it has a restrictive shell, this can be easily bypassed via the built-in ECHO shell command.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Upgrade the device to the fixed firmware build for its release branch, as listed in Uniview security notice USRC-202112-01.

The vendor also notes that exploitation requires reaching UDP port 7788 on the device. Ensure that port is not mapped to the Internet (WAN) by a router or firewall, do not configure the device as a DMZ host, and do not configure a full cone NAT.

See Also

https://ssd-disclosure.com/ssd-advisory--uniview-preauth-rce/

http://www.nessus.org/u?0de2d11a

Plugin Details

Severity: Critical

ID: 506028

File Name: tenable_ot_uniview_CVE-2021-45039.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 10/2/2026

Updated: 10/2/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:uniview:camera_firmware

Required KB Items: Tenable.ot/Uniview

Patch Publication Date: 12/22/2021

Vulnerability Publication Date: 12/22/2021

Reference Information

CVE: CVE-2021-45039

CWE: 120