Blackmagicdesign manufactures professional video production and broadcast hardware and software, including editing systems such as DaVinci Resolve and networked control appliances like the ATEM Mini Pro line and Web Presenter HD devices. Observed vulnerabilities in this portfolio cluster around information disclosure, integer-overflow conditions, authentication gaps, and uninitialized resources—weaknesses reflecting the firmware and embedded-application layers of video-processing and network-control systems. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blackmagicdesign over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40418CRITICAL When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assignment of a property containing an object referring to a UUID | Dec 22, 2021 | 9.8 | 32 | NO | NO |
CVE-2021-40417CRITICAL When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decoding parameters that were submitted with the job along with fie | Dec 22, 2021 | 9.8 | 31 | NO | NO |
CVE-2025-57441CRITICAL The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Telnet service on port 9990. Upon connection, the attacker can | Sep 22, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-57437CRITICAL The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected, the service reveals extensive | Sep 22, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-57432CRITICAL Blackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This service allows remote attackers to manipulate stream settings | Sep 22, 2025 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blackmagicdesign.
Media articles that mention a CVE ID that affects a product developed by Blackmagicdesign — matched by CVE ID, not by vendor name.