Insma produces compact IP security cameras marketed as covert or surveillance-oriented devices, with vulnerabilities concentrated in its Wi-Fi-enabled mini spy camera line and its associated firmware. The observed weakness classes—including cross-site request forgery, cross-site scripting, and unrestricted file upload—reflect common input-validation and access-control gaps in embedded web interfaces. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Insma over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-19641HIGH An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. Authenticated attackers with the "Operator" Privilege can gain admin privileges via a crafted re | Mar 30, 2021 | 8.8 | 26 | NO | NO |
CVE-2020-19639HIGH Cross Site Request Forgery (CSRF) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B, via all fields to WebUI. | Mar 30, 2021 | 8.8 | 25 | NO | NO |
CVE-2020-19640HIGH An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. An unauthenticated attacker can reboot the device causing a Denial of Service, via a hidden rebo | Mar 30, 2021 | 7.5 | 23 | NO | NO |
CVE-2020-19643MEDIUM Cross Site Scripting (XSS) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B via all fields in the FTP settings page to the "goform/formSetFtpCfg" settings p | Mar 30, 2021 | 6.1 | 21 | NO | NO |
CVE-2020-19642MEDIUM An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. A local attacker can execute arbitrary code via editing the 'recdata.db' file to call a speciall | Mar 30, 2021 | 6.2 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Insma.
Media articles that mention a CVE ID that affects a product developed by Insma — matched by CVE ID, not by vendor name.