CVE-2020-24217 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 40.3% (pctl 99)
Patch early
A public exploit exists.
Description
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly in conjunction with command injection, to achieve arbitrary code execution.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 40.3% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-306 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-10-06 |
| Last modified | 2026-06-17 |
Affected (40)
| Vendor | Product |
|---|---|
| szuray | iptv\/h.264 video encoder firmware |
| szuray | uaioe264-1u |
| szuray | uce264-1-mini |
| szuray | uce264-1wb-mini |
| szuray | uce264-4-1u |
| szuray | uce264-8-1u |
| szuray | uhae264-16 |
| szuray | uhce264-1 |
| szuray | uhce264-16p32 |
| szuray | uhce264-1p2 |
| szuray | uhce264-1p2-1u |
| szuray | uhce264-1s |
| szuray | uhce264-1w |
| szuray | uhce264-1ws |
| szuray | uhce264-4p8 |
| szuray | uhe264-1-4k |
| szuray | uhe264-16 |
| szuray | uhe264-16l-3u |
| szuray | uhe264-16s-2u |
| szuray | uhe264-1l |
| szuray | uhe264-1l-4k |
| szuray | uhe264-1lw |
| szuray | uhe264-1s |
| szuray | uhe264-1s-mini |
| szuray | uhe264-1w-mini |
| szuray | uhe264-1wb-4g |
| szuray | uhe264-1wb-mini |
| szuray | uhe264-1wbs-2b |
| szuray | uhe264-1wbs-mini |
| szuray | uhe264-1ws-mini |
| szuray | uhe264-2-1u |
| szuray | uhe264-4 |
| szuray | uhe264-4-1u |
| szuray | uhe264-4l-1u |
| szuray | uhe264-8 |
| szuray | uhe264-8-1u |
| szuray | uhe264-8l-3u |
| szuray | uhe264-8s-2u |
| szuray | use264-16-3u |
| szuray | use264-1l |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | HiSilicon Video Encoders - RCE via unauthenticated command injection | 2020-10-19 |
| exploit-db | HiSilicon video encoders - RCE via unauthenticated upload of malicious firmware | 2020-10-19 |
References
- http://packetstormsecurity.com/files/159597/HiSilicon-Video-Encoder-Command-Injection.html
- http://packetstormsecurity.com/files/159599/HiSilicon-Video-Encoder-Malicious-Firmware-Code-Execution.html
- https://kojenov.com/2020-09-15-hisilicon-encoder-vulnerabilities/
- https://www.kb.cert.org/vuls/id/896979
- http://packetstormsecurity.com/files/159597/HiSilicon-Video-Encoder-Command-Injection.html
- http://packetstormsecurity.com/files/159599/HiSilicon-Video-Encoder-Malicious-Firmware-Code-Execution.html
- https://kojenov.com/2020-09-15-hisilicon-encoder-vulnerabilities/
- https://www.kb.cert.org/vuls/id/896979
→ the Explorer · watch your stack · NVD