Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmission risk. Attackers can exploit this by eavesdropping on network requests to obtain data.Users are advised to upgrade the app to the latest version and enable the video encryption feature.
Metrics
Affected Vendors & Products
References
History
Sat, 09 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unencrypted Legacy API in EZVIZ App Enables Data Eavesdropping | |
| Weaknesses | CWE-312 |
Sat, 09 May 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmission risk. Attackers can exploit this by eavesdropping on network requests to obtain data.Users are advised to upgrade the app to the latest version and enable the video encryption feature. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hikvision
Published: 2026-05-09T08:29:09.821Z
Updated: 2026-05-09T08:29:09.821Z
Reserved: 2026-03-13T07:45:08.744Z
Link: CVE-2026-32683
No data.
Status : Received
Published: 2026-05-09T09:16:08.973
Modified: 2026-05-09T09:16:08.973
Link: CVE-2026-32683
No data.