Guardzilla produces a line of indoor and outdoor surveillance cameras and associated firmware where disclosures center on embedded-device weaknesses: OS command injection, buffer boundary violations, hard-coded credentials, and insufficient randomness in cryptographic or session contexts. These issues are characteristic of network-connected camera products and reflect the constraints of embedded firmware development. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Guardzilla over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18602CRITICAL The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring. | Dec 31, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-18601HIGH The TK_set_deviceModel_req_handle function in the cloud communication component in Guardzilla GZ621W devices with firmware 0.5.1.4 has a Buffer Overflow. | Dec 31, 2018 | 8.1 | 27 | NO | NO |
CVE-2018-18600HIGH The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter. | Dec 31, 2018 | 8.1 | 27 | NO | NO |
CVE-2018-5560HIGH A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla All-In-One Video Security System allows an attacker to view | Jan 31, 2019 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Guardzilla.
Media articles that mention a CVE ID that affects a product developed by Guardzilla — matched by CVE ID, not by vendor name.