Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Amcrest

First CVE: Sep 5, 2018Active for: 8 yearsTotal CVEs: 11
68.3
VTI Score
TOP TARGET

Amcrest manufactures a focused line of IP surveillance cameras and firmware that occupy a prominent position in the security-camera supply chain despite modest product diversity. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have an elevated tendency toward both confirmed in-the-wild exploitation and public exploit availability, reflecting the combination of default credentials, authentication bypass pathways, and memory-safety flaws that recur across its embedded imaging and network-access layers. The exposure concentrates in products such as the IPM-721S camera models and recurs through weakness classes including hard-coded credentials, improper authentication, buffer-boundary violations, and NULL-pointer dereferences characteristic of legacy firmware codebases. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
9.1%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Amcrest over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 5, 2018
7 years ago
Most Recent CVE
Apr 8, 2020
2,298 days ago

Products(42 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-5735HIGH
Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly exec
Apr 8, 20208.888YESYES
CVE-2017-8229CRITICAL
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials. If the firmware version V2.420.AC00.16.R 9/9/2016 i
Jul 3, 20199.880NOYES
CVE-2019-3948HIGH
The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R
Jul 29, 20197.550NOYES
CVE-2017-8226CRITICAL
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reverses the firmware to identify
Jul 3, 20199.831NONO
CVE-2017-13719CRITICAL
The Amcrest IPM-721S Amcrest_IPC-AWXX_Eng_N_V2.420.AC00.17.R.20170322 allows HTTP requests that permit enabling various functionalities of the camera by using HTTP APIs, instead of
Jul 3, 20199.831NONO
CVE-2017-8227CRITICAL
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have a timeout policy to wait for 5 minutes in case 30 incorrect password attempts are detected using the Web and HTTP API interf
Jul 3, 20199.830NONO
CVE-2017-8230HIGH
On Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices, the users on the device are divided into 2 groups "admin" and "user". However, as a part of security analysis it was identifi
Jul 3, 20198.827NONO
CVE-2017-8228HIGH
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices mishandle reboots within the past two hours. Amcrest cloud services does not perform a thorough verification when allowing the us
Jul 3, 20198.827NONO
CVE-2018-16546MEDIUM
Amcrest networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechani
Sep 5, 20185.921NONO
CVE-2020-5736MEDIUM
Amcrest cameras and NVR are vulnerable to a null pointer dereference over port 37777. An authenticated remote attacker can abuse this issue to crash the device.
Apr 8, 20206.518NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
27%
36%
36%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low3 (27.3%)
High0 (0.0%)
None8 (72.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
1 CVE
9.1% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
9.1% of CVEs· 96th percentile
ExploitDB
2 CVEs
18.2% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Amcrest.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Amcrest — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Amcrest's Products

View all 2 CNAs →

Top CWEs