xiongmaitech CVE Vulnerabilities & Metrics

Focus on xiongmaitech vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About xiongmaitech Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with xiongmaitech. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total xiongmaitech CVEs: 15
Earliest CVE date: 07 Apr 2017, 04:59 UTC
Latest CVE date: 11 Sep 2023, 19:15 UTC

Latest CVE reference: CVE-2023-39068

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical xiongmaitech CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.55

Max CVSS: 10.0

Critical CVEs (≥9): 3

CVSS Range vs. Count

Range Count
0.0-3.9 6
4.0-6.9 5
7.0-8.9 1
9.0-10.0 3

CVSS Distribution Chart

Top 5 Highest CVSS xiongmaitech CVEs

These are the five CVEs with the highest CVSS scores for xiongmaitech, sorted by severity first and recency.

All CVEs for xiongmaitech

CVE-2023-39068 xiongmaitech vulnerability CVSS: 0 11 Sep 2023, 19:15 UTC

Buffer Overflow vulnerability in NBD80S09S-KLC v.YK_HZXM_NBD80S09S-KLC_V4.03.R11.7601.Nat.OnvifC.20230414.bin and NBD80N32RA-KL-V3 v.YK_HZXM_NBD80N32RA-KL_V4.03.R11.7601.Nat.OnvifC.20220120.bin allows a remote attacker to casue a denial of service via a crafted request to the service.XM component.

CVE-2022-45460 xiongmaitech vulnerability CVSS: 0 28 Mar 2023, 22:15 UTC

Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow an unauthenticated and remote user to exploit a stack-based buffer overflow and crash the web server, resulting in a system reboot. An unauthenticated and remote attacker can execute arbitrary code by sending a crafted HTTP request that triggers the overflow condition via a long URI passed to a sprintf call. NOTE: this is different than CVE-2018-10088, but this may overlap CVE-2017-16725.

CVE-2022-45045 xiongmaitech vulnerability CVSS: 0 01 Dec 2022, 05:15 UTC

Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and authenticated attacker, possibly using the default admin:tlJwpbo6 credentials, can connect to port 34567 and execute arbitrary operating system commands via a crafted JSON file during an upgrade request. Since at least 2021, Xiongmai has applied patches to prevent attackers from using this mechanism to execute telnetd.

CVE-2021-38828 xiongmaitech vulnerability CVSS: 0 14 Nov 2022, 02:15 UTC

Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to plain-text traffic sniffing.

CVE-2021-38827 xiongmaitech vulnerability CVSS: 0 14 Nov 2022, 02:15 UTC

Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to account takeover.

CVE-2021-41506 xiongmaitech vulnerability CVSS: 10.0 30 Jun 2022, 13:15 UTC

Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4.02.R11.7601.Nat.Onvif.20170424, V4.02.R11.Nat.Onvif.20170327, V4.02.R11.Nat.Onvif.20161205, V4.02.R11.Nat.20170301, V4.02.R12.Nat.OnvifS.20170727 is affected by a backdoor in the macGuarder and dvrHelper binaries of DVR/NVR/IP camera firmware due to static root account credentials in the system.

CVE-2020-22253 xiongmaitech vulnerability CVSS: 7.5 06 Apr 2022, 23:15 UTC

Xiongmai Technology Co devices AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, and HI3518E_50H10L_S39 were all discovered to have port 9530 open which allows unauthenticated attackers to make arbitrary Telnet connections with the victim device.

CVE-2022-26259 xiongmaitech vulnerability CVSS: 4.6 28 Mar 2022, 01:15 UTC

A buffer over flow in Xiongmai DVR devices NBD80X16S-KL, NBD80X09S-KL, NBD80X08S-KL, NBD80X09RA-KL, AHB80X04R-MH, AHB80X04R-MH-V2, AHB80X04-R-MH-V3, AHB80N16T-GS, AHB80N32F4-LME, and NBD90S0VT-QW allows attackers to cause a Denial of Service (DoS) via a crafted RSTP request.

CVE-2019-11878 xiongmaitech vulnerability CVSS: 3.3 10 May 2019, 15:29 UTC

An issue was discovered on XiongMai Besder IP20H1 V4.02.R12.00035520.12012.047500.00200 cameras. An attacker on the same local network as the camera can craft a message with a size field larger than 0x80000000 and send it to the camera, related to an integer overflow or use of a negative number. This then crashes the camera for about 120 seconds.

CVE-2018-17919 xiongmaitech vulnerability CVSS: 6.4 10 Oct 2018, 15:29 UTC

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with its default password to login to XMeye and access/view video streams.

CVE-2018-17917 xiongmaitech vulnerability CVSS: 5.0 10 Oct 2018, 15:29 UTC

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potential Cloud IDs. Using this ID, the attacker can discover and connect to valid devices using one of the supported apps.

CVE-2018-17915 xiongmaitech vulnerability CVSS: 6.4 10 Oct 2018, 15:29 UTC

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server do not encrypt all device communication. This includes the XMeye service and firmware update communication. This could allow an attacker to eavesdrop on video feeds, steal XMeye login credentials, or impersonate the update server with malicious update code.

CVE-2018-10088 xiongmaitech vulnerability CVSS: 10.0 08 Jun 2018, 12:29 UTC

Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.

CVE-2017-16725 xiongmaitech vulnerability CVSS: 10.0 20 Dec 2017, 19:29 UTC

A Stack-based Buffer Overflow issue was discovered in Xiongmai Technology IP Cameras and DVRs using the NetSurveillance Web interface. The stack-based buffer overflow vulnerability has been identified, which may allow an attacker to execute code remotely or crash the device. After rebooting, the device restores itself to a more vulnerable state in which Telnet is accessible.

CVE-2017-7577 xiongmaitech vulnerability CVSS: 5.0 07 Apr 2017, 04:59 UTC

XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request.