Hisilicon manufactures embedded system-on-chip designs and firmware for networked surveillance and video-processing devices, with documented vulnerabilities concentrated in its Hi3510 and Hi3516 encoder product lines. The recurring weaknesses observed across these products center on permission and access-control issues, memory-safety flaws, and insufficient information in vulnerability disclosures, patterns typical of firmware-based embedded systems with limited transparency in their development lifecycle. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hisilicon over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11560CRITICAL A buffer overflow vulnerability in the streaming server provided by hisilicon in HI3516 models allows an unauthenticated attacker to remotely run arbitrary code by sending a specia | May 7, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-10710HIGH Insecure permissions in the Web management portal on all IP cameras based on Hisilicon Hi3510 firmware allow authenticated attackers to receive a network's cleartext WiFi credentia | Apr 23, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-10711HIGH Incorrect access control in the RTSP stream and web portal on all IP cameras based on Hisilicon Hi3510 firmware (until Webware version V1.0.1) allows attackers to view an RTSP stre | Apr 23, 2019 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hisilicon.
Media articles that mention a CVE ID that affects a product developed by Hisilicon — matched by CVE ID, not by vendor name.