Sricam manufactures a line of compact networked camera products and management software, including models such as the SH016, SH024, SH026, and SH027, alongside its DeviceViewer control application. The observed vulnerability patterns center on memory-safety issues including out-of-bounds writes and stack-based buffer overflows, along with authentication-implementation weaknesses, reflecting the typical challenges of embedded firmware and IoT device software. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sricam over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-6973HIGH Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is configured for an iterative queuei | Mar 21, 2019 | 7.5 | 34 | NO | YES |
CVE-2019-25062HIGH A vulnerability was found in Sricam IP CCTV Camera and classified as critical. This issue affects some unknown processing of the component Device Viewer. The manipulation leads to | Jun 8, 2022 | 7.8 | 26 | NO | NO |
CVE-2019-25435HIGH Sricam DeviceViewer 3.12.0.1 contains a local buffer overflow vulnerability in the user management add user function that allows authenticated attackers to execute arbitrary code b | Feb 20, 2026 | 7.8 | 25 | NO | NO |
CVE-2019-25063HIGH A vulnerability was found in Sricam IP CCTV Camera. It has been classified as critical. Affected is an unknown function of the component Device Viewer. The manipulation leads to me | Jun 8, 2022 | 7.8 | 25 | NO | NO |
CVE-2019-25436MEDIUM Sricam DeviceViewer 3.12.0.1 contains a password change security bypass vulnerability that allows authenticated users to change passwords without proper validation of the old passw | Feb 20, 2026 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sricam.
Media articles that mention a CVE ID that affects a product developed by Sricam — matched by CVE ID, not by vendor name.