resources

Camera CVE tracker

This page lists published camera, NVR, and DVR CVEs and flags which ones CISA has listed as exploited in the wild. 173 rows on this build, 21 of them from the Known Exploited Vulnerabilities catalog.

Updated August 19, 2026. Sources: the CISA Known Exploited Vulnerabilities catalog, Axis security advisories, Bosch PSIRT, and Hanwha Vision S-CERT. Free to cite with a link.

173

Published camera CVEs on this page

21

Of those, listed in KEV

152

Axis, Bosch, or Hanwha published

0

Axis, Bosch, or Hanwha in KEV

A published CVE means a vulnerability was documented. A KEV Yes means CISA has evidence it has been used. Most camera CVEs never make the KEV catalog. The ones that do are the doors that already opened somewhere, which is why patch latency on those rows is a fleet problem rather than a research problem. How those doors get walked, and what closes them, is in IP camera vulnerabilities.

Axis, Bosch, and Hanwha publish camera CVEs on their own advisory pages, and those rows are in this table. CISA currently lists none of them as exploited in the wild. That is a statement about KEV, not a claim those products have no vulnerabilities.

Vendor-published camera CVEs and CISA KEV are different lists. This page merges both and flags the KEV subset. Axis, Bosch, and Hanwha currently have zero camera-shaped KEV rows. Published CVEs and the KEV subset are different lists. Vendor published Axis, Bosch, Hanwha 152 CVEs This page 173 published CVEs 21 in the wild Supported in KEV Axis, Bosch, Hanwha 0 rows a KEV listing is evidence of use somewhere, not a finding on your fleet
Axis, Bosch, and Hanwha publish camera CVEs. CISA KEV is the smaller set with evidence of exploitation in the wild. None of those three brands currently have a camera-shaped KEV row.

the table

Published camera-shaped CVEs, current as of August 19, 2026.

CVE Vendor Product In the wild Date CWE
CVE-2017-7921 Hikvision Multiple Products Yes Mar 5, 2026 CWE-287
CVE-2023-52163 Digiever DS-2105 Pro Yes Dec 22, 2025 CWE-862
CVE-2022-40799 D-Link DNR-322L Yes Aug 5, 2025 CWE-494
CVE-2020-25079 D-Link DCS-2530L and DCS-2670L Devices Yes Aug 5, 2025 CWE-77
CVE-2020-25078 D-Link DCS-2530L and DCS-2670L Devices Yes Aug 5, 2025 none
CVE-2024-6047 GeoVision Multiple Devices Yes May 7, 2025 CWE-78
CVE-2024-11120 GeoVision Multiple Devices Yes May 7, 2025 CWE-78
CVE-2025-1316 Edimax IC-7100 IP Camera Yes Mar 19, 2025 CWE-78
CVE-2022-23227 NUUO NVRmini2 Devices Yes Dec 18, 2024 CWE-306
CVE-2021-40407 Reolink RLC-410W IP Camera Yes Dec 18, 2024 CWE-78
CVE-2019-11001 Reolink Multiple IP Cameras Yes Dec 18, 2024 CWE-78
CVE-2018-14933 NUUO NVRmini Devices Yes Dec 18, 2024 CWE-78
CVE-2024-8957 PTZOptics PT30X-SDI/NDI Cameras Yes Nov 4, 2024 CWE-78
CVE-2024-8956 PTZOptics PT30X-SDI/NDI Cameras Yes Nov 4, 2024 CWE-287
CVE-2021-33045 Dahua IP Camera Firmware Yes Aug 21, 2024 CWE-287
CVE-2021-33044 Dahua IP Camera Firmware Yes Aug 21, 2024 CWE-287
CVE-2023-47565 QNAP VioStor NVR Yes Dec 21, 2023 CWE-78
CVE-2016-11021 D-Link DCS-930L Devices Yes Mar 25, 2022 CWE-78
CVE-2021-36260 Hikvision Security cameras web server Yes Jan 10, 2022 CWE-78
CVE-2020-5735 Amcrest Cameras and Network Video Recorder (NVR) Yes Nov 3, 2021 CWE-121
CVE-2019-20085 TVT NVMS-1000 Yes Nov 3, 2021 CWE-22
CVE-2026-6505 Axis AXIS OS No none
CVE-2026-6181 Axis AXIS OS No none
CVE-2026-5304 Axis AXIS OS No none
CVE-2026-5303 Axis AXIS OS No none
CVE-2026-4757 Axis AXIS OS No none
CVE-2026-1185 Axis AXIS OS No none
CVE-2026-0804 Axis AXIS OS No none
CVE-2026-0802 Axis AXIS OS No none
CVE-2026-0541 Axis AXIS OS No none
CVE-2025-52601 Hanwha Cameras No none
CVE-2025-52600 Hanwha Cameras No none
CVE-2025-52599 Hanwha Cameras No none
CVE-2025-52598 Hanwha Cameras No none
CVE-2025-30027 Axis AXIS OS No none
CVE-2025-11142 Axis AXIS OS No none
CVE-2025-9524 Axis AXIS OS No none
CVE-2025-9055 Axis AXIS OS No none
CVE-2025-8998 Axis AXIS OS No none
CVE-2025-8108 Axis AXIS OS No none
CVE-2025-8075 Hanwha Cameras No none
CVE-2025-6779 Axis AXIS OS No none
CVE-2025-6571 Axis AXIS OS No none
CVE-2025-6298 Axis AXIS OS No none
CVE-2025-5718 Axis AXIS OS No none
CVE-2025-5454 Axis AXIS OS No none
CVE-2025-5452 Axis AXIS OS No none
CVE-2025-4645 Axis AXIS OS No none
CVE-2025-3892 Axis AXIS OS No none
CVE-2025-0361 Axis AXIS OS No none
CVE-2025-0360 Axis AXIS OS No none
CVE-2025-0359 Axis AXIS OS No none
CVE-2025-0358 Axis AXIS OS No none
CVE-2025-0325 Axis AXIS OS No none
CVE-2025-0324 Axis AXIS OS No none
CVE-2024-58330 Bosch IP cameras (CPP) No Aug 21, 2024 none
CVE-2024-54013 Hanwha Cameras No none
CVE-2024-54012 Hanwha Cameras No none
CVE-2024-54011 Hanwha Cameras No none
CVE-2024-47262 Axis AXIS OS No none
CVE-2024-47261 Axis AXIS OS No none
CVE-2024-47260 Axis AXIS OS No none
CVE-2024-47259 Axis AXIS OS No none
CVE-2024-47257 Axis AXIS OS No none
CVE-2024-41887 Hanwha NVR No none
CVE-2024-41886 Hanwha NVR No none
CVE-2024-41885 Hanwha NVR No none
CVE-2024-41884 Hanwha NVR No none
CVE-2024-41883 Hanwha NVR No none
CVE-2024-41882 Hanwha NVR No none
CVE-2024-8772 Axis AXIS OS No none
CVE-2024-8160 Axis AXIS OS No none
CVE-2024-7784 Axis AXIS OS No none
CVE-2024-6979 Axis AXIS OS No none
CVE-2024-6509 Axis AXIS OS No none
CVE-2024-6173 Axis AXIS OS No none
CVE-2024-0067 Axis AXIS OS No none
CVE-2024-0066 Axis AXIS OS No none
CVE-2024-0055 Axis AXIS OS No none
CVE-2024-0054 Axis AXIS OS No none
CVE-2023-39509 Bosch IP cameras (CPP) No Dec 13, 2023 none
CVE-2023-5747 Hanwha Cameras No Nov 13, 2023 none
CVE-2022-41677 Bosch IP cameras (CPP) No Jun 28, 2023 none
CVE-2023-32229 Bosch IP cameras (CPP) No May 31, 2023 none
CVE-2023-31996 Hanwha Cameras No May 15, 2023 none
CVE-2023-31995 Hanwha Cameras No May 15, 2023 none
CVE-2023-31994 Hanwha Cameras No May 15, 2023 none
CVE-2023-21418 Axis AXIS OS No none
CVE-2023-21417 Axis AXIS OS No none
CVE-2023-21416 Axis AXIS OS No none
CVE-2023-21415 Axis AXIS OS No none
CVE-2023-21414 Axis AXIS OS No none
CVE-2023-21413 Axis AXIS OS No none
CVE-2023-21412 Axis AXIS License Plate Verifier No none
CVE-2023-21411 Axis AXIS License Plate Verifier No none
CVE-2023-21410 Axis AXIS License Plate Verifier No none
CVE-2023-21409 Axis AXIS License Plate Verifier No none
CVE-2023-21408 Axis AXIS License Plate Verifier No none
CVE-2023-21407 Axis AXIS License Plate Verifier No none
CVE-2023-21406 Axis AXIS OS No none
CVE-2023-21405 Axis AXIS OS No none
CVE-2023-21404 Axis AXIS OS No none
CVE-2023-6116 Hanwha NVR and DVR No none
CVE-2023-6096 Hanwha NVR and DVR No none
CVE-2023-6095 Hanwha NVR and DVR No none
CVE-2023-5800 Axis AXIS OS No none
CVE-2023-5677 Axis AXIS OS No none
CVE-2023-5553 Axis AXIS OS No none
CVE-2023-5038 Hanwha Cameras No none
CVE-2023-5037 Hanwha Cameras No none
CVE-2021-23851 Bosch IP cameras (CPP) No Mar 30, 2022 none
CVE-2021-23850 Bosch IP cameras (CPP) No Mar 30, 2022 none
CVE-2021-32934 Hanwha NVR No Sep 9, 2021 none
CVE-2021-28372 Hanwha NVR No Sep 9, 2021 none
CVE-2021-23849 Bosch IP cameras (CPP) No Aug 4, 2021 none
CVE-2021-23854 Bosch IP cameras (CPP) No Jun 9, 2021 none
CVE-2021-23853 Bosch IP cameras (CPP) No Jun 9, 2021 none
CVE-2021-23852 Bosch IP cameras (CPP) No Jun 9, 2021 none
CVE-2021-23848 Bosch IP cameras (CPP) No Jun 9, 2021 none
CVE-2021-23847 Bosch IP cameras (CPP) No Jun 9, 2021 none
CVE-2021-3011 Bosch IP cameras and encoders (CPP) No Mar 3, 2021 none
CVE-2021-31988 Axis AXIS OS No none
CVE-2021-31987 Axis AXIS OS No none
CVE-2021-31986 Axis AXIS OS No none
CVE-2019-12223 Hanwha NVR No none
CVE-2018-19036 Bosch IP cameras (CPP) No Dec 12, 2018 none
CVE-2018-6303 Hanwha SmartCam No Mar 21, 2018 none
CVE-2018-6302 Hanwha SmartCam No Mar 21, 2018 none
CVE-2018-6301 Hanwha SmartCam No Mar 21, 2018 none
CVE-2018-6300 Hanwha SmartCam No Mar 21, 2018 none
CVE-2018-6299 Hanwha SmartCam No Mar 21, 2018 none
CVE-2018-6298 Hanwha SmartCam No Mar 21, 2018 none
CVE-2018-6297 Hanwha SmartCam No Mar 21, 2018 none
CVE-2018-6296 Hanwha SmartCam No Mar 21, 2018 none
CVE-2018-6295 Hanwha SmartCam No Mar 21, 2018 none
CVE-2018-6294 Hanwha SmartCam No Mar 21, 2018 none
CVE-2018-11689 Hanwha DVR No none
CVE-2018-10664 Axis AXIS OS No none
CVE-2018-10663 Axis AXIS OS No none
CVE-2018-10662 Axis AXIS OS No none
CVE-2018-10661 Axis AXIS OS No none
CVE-2018-10660 Axis AXIS OS No none
CVE-2018-10659 Axis AXIS OS No none
CVE-2018-10658 Axis AXIS OS No none
CVE-2018-9158 Axis AXIS OS No none
CVE-2017-20049 Axis AXIS OS No none
CVE-2017-15885 Axis AXIS OS No none
CVE-2017-12413 Axis AXIS OS No none
CVE-2017-7912 Hanwha NVR No none
CVE-2015-8258 Axis AXIS OS No none
CVE-2015-8257 Axis AXIS OS No none
CVE-2015-8256 Axis AXIS OS No none
CVE-2015-8255 Axis AXIS OS No none
CVE-2013-3543 Axis AXIS OS No none
CVE-2008-5260 Axis AXIS OS No none
CVE-2007-5214 Axis AXIS OS No none
CVE-2007-5213 Axis AXIS OS No none
CVE-2007-5212 Axis AXIS OS No none
CVE-2007-4930 Axis AXIS OS No none
CVE-2007-4929 Axis AXIS OS No none
CVE-2007-4928 Axis AXIS OS No none
CVE-2007-4927 Axis AXIS OS No none
CVE-2007-4926 Axis AXIS OS No none
CVE-2007-2239 Axis AXIS OS No none
CVE-2004-2427 Axis AXIS OS No none
CVE-2004-2426 Axis AXIS OS No none
CVE-2004-2425 Axis AXIS OS No none
CVE-2004-0789 Axis AXIS OS No none
CVE-2003-1386 Axis AXIS OS No none
CVE-2003-0240 Axis AXIS OS No none
CVE-2001-1543 Axis AXIS OS No none
CVE-2000-0191 Axis AXIS OS No none
CVE-2000-0144 Axis AXIS OS No none

For KEV rows, Date is the day CISA added the identifier, not the day the CVE was published. CVE-2017-7921 is a 2017 Hikvision authentication bypass that landed on KEV in March 2026. Vendor rows use the advisory date when the vendor publishes one. Axis registry tables have no calendar column. Hanwha RSS stamps are the feed rebuild, not the advisory date, so those stay blank unless the PDF filename itself carries a date. Blank dates sort by CVE identifier.

Methodology

Two feeds, rebuilt on a monthly cadence, free to cite. The first is CISA's public KEV JSON, the same catalog CISA publishes for BOD 22-01: vulnerabilities with evidence of exploitation in the wild. This page keeps the camera-shaped slice of that catalog. The second is vendor PSIRT: Axis security advisories, Bosch PSIRT camera and CPP-titled advisories, and Hanwha Vision S-CERT vulnerability reports for cameras, NVRs, and DVRs. A CVE that appears in both feeds is one row, marked Yes for in the wild.

The KEV slice keeps a row when the vendor is a camera or recorder manufacturer (Hikvision, Dahua, Amcrest, Reolink, NUUO, PTZOptics, GeoVision, Digiever, TVT), or when the product field is camera-shaped for vendors that also ship other gear (Edimax IP cameras, QNAP VioStor NVR, D-Link DCS and DNR). Those names dominate the in-the-wild column because that catalog is the slice where CISA has evidence of exploitation. Hikvision and Dahua stay KEV-only here. This page does not scrape NVD for those brands. The slice also keeps intercoms, door stations, and network speakers when a feed lists them. Rows for fire alarm, access control, media servers, camera-upload features on non-camera products, UniFi, PBX, NAS, and the rest of a vendor's IT catalog are dropped. Axis Camera Station, AXIS Device Manager, Bosch Rexroth, Bosch MAP, and Hanwha VMS or statement PDFs are out of scope. Axis IDs still under embargo, listed without a published summary, are excluded until Axis publishes the advisory text.

Two caveats matter for interpretation. First, KEV is not a complete history of camera exploitation. CISA adds rows as evidence meets its bar, sometimes years after disclosure. Second, a listing is not a finding that a given fleet is vulnerable. The product string can be as broad as "Multiple Products" or "AXIS OS." A model search (M3005-V) maps the model to a vendor and shows that vendor's camera CVEs; it does not mean every listed CVE affects that camera. Confirm against inventory, firmware, and the vendor advisory linked from NVD. If a vendor scrape fails at refresh time, the last successful pull for that vendor is kept rather than emptying the table.

Journalists, researchers, and operators are welcome to cite and republish these figures with a link back to this page so readers can check the method and the current feeds. If a row looks wrong, write [email protected] with a source.

Questions about this tracker

What does this list include?

Published camera, NVR, and DVR CVEs from vendor advisories and from CISA KEV. Each row is flagged Yes or No for whether CISA has listed that identifier as exploited in the wild.

Can I search by camera model?

Yes. A model such as M3005-V maps to its vendor and shows that vendor's camera CVEs. Axis publishes against AXIS OS, Bosch against CPP platforms, so a model hit is not a finding that every listed CVE affects that camera. Confirm the advisory and the firmware actually running. Common current models also live on the camera firmware tracks reference.

Does a listing mean my cameras are vulnerable?

No. It means the vulnerability was published, and the In the wild column says whether CISA has evidence it has been used somewhere. Whether it applies depends on vendor, product, firmware, and whether the management path is reachable.

Why is the Axis, Bosch, and Hanwha KEV count zero?

Those vendors publish camera CVEs, and those rows are in the table. CISA currently lists none of them as exploited in the wild. That is not a claim they have no vulnerabilities.

How often is it updated?

Monthly, or when CISA adds a camera-shaped row or a vendor publishes a new camera advisory. Catalog version on this build is 2026.08.19.

Holding these closed across a fleet

The operational problem is knowing whether any of these products, or firmware old enough to carry them, is still installed. MentatNOC continuously watches firmware currency and credential posture on every camera, runs campaigns in staged waves with automatic rollback, and records every check and change in an audit log built so entries cannot be rewritten after the fact. It monitors device health, not video. The action set is on platform actions, and the fastest way to see a fleet's posture is a live platform demo.

the list is the easy part

Know which cameras still run firmware that belongs on this list.

Firmware currency, credentials, and change history for every camera, updated as the vendors move.