Amcrest manufactures a focused line of IP surveillance cameras and firmware that occupy a prominent position in the security-camera supply chain despite modest product diversity. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have an elevated tendency toward both confirmed in-the-wild exploitation and public exploit availability, reflecting the combination of default credentials, authentication bypass pathways, and memory-safety flaws that recur across its embedded imaging and network-access layers. The exposure concentrates in products such as the IPM-721S camera models and recurs through weakness classes including hard-coded credentials, improper authentication, buffer-boundary violations, and NULL-pointer dereferences characteristic of legacy firmware codebases. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Amcrest over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-5735HIGH Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly exec | Apr 8, 2020 | 8.8 | 88 | YES | YES |
CVE-2017-8229CRITICAL Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials. If the firmware version V2.420.AC00.16.R 9/9/2016 i | Jul 3, 2019 | 9.8 | 80 | NO | YES |
CVE-2019-3948HIGH The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R | Jul 29, 2019 | 7.5 | 50 | NO | YES |
CVE-2017-8226CRITICAL Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reverses the firmware to identify | Jul 3, 2019 | 9.8 | 31 | NO | NO |
CVE-2017-13719CRITICAL The Amcrest IPM-721S Amcrest_IPC-AWXX_Eng_N_V2.420.AC00.17.R.20170322 allows HTTP requests that permit enabling various functionalities of the camera by using HTTP APIs, instead of | Jul 3, 2019 | 9.8 | 31 | NO | NO |
CVE-2017-8227CRITICAL Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have a timeout policy to wait for 5 minutes in case 30 incorrect password attempts are detected using the Web and HTTP API interf | Jul 3, 2019 | 9.8 | 30 | NO | NO |
CVE-2017-8230HIGH On Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices, the users on the device are divided into 2 groups "admin" and "user". However, as a part of security analysis it was identifi | Jul 3, 2019 | 8.8 | 27 | NO | NO |
CVE-2017-8228HIGH Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices mishandle reboots within the past two hours. Amcrest cloud services does not perform a thorough verification when allowing the us | Jul 3, 2019 | 8.8 | 27 | NO | NO |
CVE-2018-16546MEDIUM Amcrest networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechani | Sep 5, 2018 | 5.9 | 21 | NO | NO |
CVE-2020-5736MEDIUM Amcrest cameras and NVR are vulnerable to a null pointer dereference over port 37777. An authenticated remote attacker can abuse this issue to crash the device. | Apr 8, 2020 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Amcrest.
Media articles that mention a CVE ID that affects a product developed by Amcrest — matched by CVE ID, not by vendor name.