CVE-2023-5747
Hanwha Vision
- Published
- 13 November 2023
- Last modified
- 17 June 2026
- CVSS
- 8.8 v3.1
- Severity
- high
- EPSS
- 0.6% (45th pct)
- CISA KEV
- Not listed
- NVD status
- Modified
- Weaknesses
- CWE-345, CWE-347
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation of Wave on the camera device. The Wave server application in camera device was vulnerable to command injection allowing an attacker to run arbitrary code. HanwhaVision has released patched firmware for the highlighted flaw. Please refer to the hanwhavision security report for more information and solution."
Exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 0.6% probability of exploitation activity in the next 30 days.
Affected products
| Product | Vendor | Type | Versions named |
|---|---|---|---|
| Pno-a6081r-e1t | Hanwha Vision | unknown | 2.21.02 |
| Pno-a6081r-e2t | Hanwha Vision | unknown | 2.21.02 |
| Wave Server Software | Hanwha Vision | unknown | < 5.1.1.37647 |
References
- https://www.hanwhavision.com/wp-content/uploads/2023/11/Camera-Vulnerability-Report-CVE-2023-5747_20231113.pdf third-party
- https://www.hanwhavision.com/wp-content/uploads/2023/11/Camera-Vulnerability-Report-CVE-2023-5747_20231113.pdf third-party
Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.