Zavio manufactures a line of compact IP cameras and firmware for small-business surveillance, with its vulnerability footprint concentrating across products such as the B8220, B8520, and CB6231 models. The vendor's disclosures skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven by recurrent memory-safety weaknesses—including stack-based buffer overflows and out-of-bounds writes—alongside authentication flaws such as hard-coded credentials and OS command injection that expose these devices to remote compromise. Defenders should prioritize inventory and network segmentation of affected camera models, as their internet-facing deployment and firmware-update inertia amplify exposure; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zavio over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2568CRITICAL A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a remote malicious user execute ar | Jan 29, 2020 | 9.8 | 67 | NO | YES |
CVE-2013-2570CRITICAL A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the binary /opt/cgi/view/param, whic | Jan 29, 2020 | 9.8 | 55 | NO | YES |
CVE-2023-3959CRITICAL Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,
CB6231, B8520, B8220, and CD321
IP Cameras
with firmware version M2.1.6.05 are
vulnerable to multiple instances o | Nov 8, 2023 | 9.8 | 54 | NO | NO |
CVE-2013-2569HIGH A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could let a malicious user obtain un | Jan 29, 2020 | 7.5 | 46 | NO | YES |
CVE-2013-2567HIGH An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.conf, which lets a remote malici | Jan 29, 2020 | 7.5 | 40 | NO | YES |
CVE-2023-4249CRITICAL Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,
CB6231, B8520, B8220, and CD321
IP Cameras
with firmware version M2.1.6.05 has a
command injection vulnerability | Nov 8, 2023 | 9.8 | 37 | NO | NO |
CVE-2023-43755CRITICAL Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,
CB6231, B8520, B8220, and CD321
IP Cameras
with firmware version M2.1.6.05 are
vulnerable to multiple instances | Nov 8, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-39435CRITICAL Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,
CB6231, B8520, B8220, and CD321 IP Cameras
with firmware version M2.1.6.05 are
vulnerable to stack-based overflows | Nov 8, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-45225CRITICAL Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220,
CB6231, B8520, B8220, and CD321
IP Cameras with firmware version M2.1.6.05 are
vulnerable to multiple instances o | Nov 8, 2023 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zavio.
Media articles that mention a CVE ID that affects a product developed by Zavio — matched by CVE ID, not by vendor name.