Ezviz manufactures a focused line of networked surveillance cameras and related firmware, a modestly represented but prominently deployed product category in the connected-device landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur across camera models through weakness classes including out-of-bounds writes, stack-based buffer overflows, improper authentication, and improper initialization—patterns characteristic of embedded firmware with constrained validation and memory-safety practices. Defenders should prioritize inventory and patching of affected camera deployments, particularly those exposed to untrusted networks; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ezviz over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2471CRITICAL Stack-based Buffer Overflow vulnerability in the EZVIZ Motion Detection component as used in camera models CS-CV248, CS-C6N-A0-1C2WFR, CS-DB1C-A0-1E2W2FR, CS-C6N-B0-1G2WF, CS-C3W-A | Sep 15, 2022 | 9.8 | 32 | NO | NO |
CVE-2023-34552HIGH In certain EZVIZ products, two stack based buffer overflows in mulicast_parse_sadp_packet and mulicast_get_pack_type functions of the SADP multicast protocol can allow an unauthent | Aug 1, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-41613HIGH EzViz Studio v2.2.0 is vulnerable to DLL hijacking. | Dec 4, 2023 | 7.8 | 25 | NO | NO |
CVE-2023-34551HIGH In certain EZVIZ products, two stack buffer overflows in netClientSetWlanCfg function of the EZVIZ SDK command server can allow an authenticated attacker present on the same local | Aug 1, 2023 | 8.0 | 24 | NO | NO |
CVE-2022-2472MEDIUM Improper Initialization vulnerability in the local server component of EZVIZ CS-C6N-A0-1C2WFR allows a local attacker to read the contents of the memory space containing the encryp | Sep 15, 2022 | 5.5 | 21 | NO | NO |
CVE-2023-48121MEDIUM An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 20230401, Ezviz CS-CV310-xxx prior to v5.3.x build 20230401, Ezviz | Nov 28, 2023 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ezviz.
Media articles that mention a CVE ID that affects a product developed by Ezviz — matched by CVE ID, not by vendor name.