CVE-2018-17915 affects all versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server, where it fails to encrypt all device communication, including the XMeye service and firmware updates. This critical vulnerability (CVSS 9.8) allows unauthenticated attackers to eavesdrop on video feeds, steal login credentials, or deliver malicious firmware updates due to the lack of encryption. Despite its high severity and potential for complete compromise (C:H/I:H/A:H), there is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:xiongmaitech:xmeye_p2p_cloud_server:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.