Back to overview

CVE-2026-56414

HIGH
7.2
CVSS 3.1
Description
A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of unexpected or malformed data in locations intended for trusted certificate material, which could affect system integrity or behavior even after reboot.

Metadata

CVE ID
CVE-2026-56414
State
PUBLISHED
Assigner
icscert
Reserved
2026-06-22 20:13 UTC
Published
2026-06-26 23:00 UTC
Last updated
2026-06-26 23:00 UTC
Primary CWE
CWE-434
CWE-434
Vendor / Product
H.VIEW / HV-500S6 IP Camera
Sources
cve.org  ·  NVD

Severity & Metrics

7.2 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
H.VIEW HV-500S6 IP Camera IPCAM_V4.06.88.251229
Weakness (CWE)
CWESourceDescription
CWE-434 cna CWE-434
CVSS scores (2)
ScoreSeverityVersionSourceVector
8.6 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
7.2 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Back to overview