Sannce develops a focused line of consumer smart security cameras, with observed vulnerabilities centered on its Smart HD WiFi Security Camera product and firmware. The durable signal reflects authentication and password-handling weaknesses typical of networked consumer devices with limited cryptographic sophistication. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sannce over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-20467CRITICAL An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. The device by default has a TELNET interface available (which is not advertised or func | Jul 22, 2021 | 9.8 | 32 | NO | NO |
CVE-2019-20464HIGH An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. By default, a mobile application is used to stream over UDP. However, the device offers | Apr 2, 2021 | 7.5 | 25 | NO | NO |
CVE-2019-20466HIGH An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. A local attacker with the "default" account is capable of reading the /etc/passwd file, | Apr 2, 2021 | 7.8 | 24 | NO | NO |
CVE-2019-20465HIGH An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. It is possible (using TELNET without a password) to control the camera's pan/zoom/tilt | Apr 2, 2021 | 7.5 | 24 | NO | NO |
CVE-2019-20463HIGH An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. A crash and reboot can be triggered by crafted IP traffic, as demonstrated by the Nikto | Apr 2, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sannce.
Media articles that mention a CVE ID that affects a product developed by Sannce — matched by CVE ID, not by vendor name.