Vulnerability record · CVE-2020-5735 · published 8 April 2020
CVE-2020-5735: Amcrest cameras and NVR stack buffer overflow on port 37777
Amcrest · 1080 Lite 8ch Firmware
Amcrest cameras and NVR firmware contain a stack-based buffer overflow reachable over TCP port 37777. An authenticated remote attacker can send crafted input to crash the device and potentially execute arbitrary code. Because these are network-facing surveillance devices, a compromise can expose video feeds and provide a foothold inside the network.
Description
Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is a remotely reachable memory corruption issue with a CVSS of 8.8 and confirmed exploitation in CISA's KEV catalog, though it requires valid credentials.
What it is
Amcrest cameras and NVR firmware contain a stack-based buffer overflow reachable over TCP port 37777. An authenticated remote attacker can send crafted input to crash the device and potentially execute arbitrary code. Because these are network-facing surveillance devices, a compromise can expose video feeds and provide a foothold inside the network.
Impact
An attacker with valid credentials can crash the device and possibly achieve remote code execution, gaining control of the camera or NVR. That control can be used to disrupt recording, access video, or pivot further into the network.
Attack surface
The flaw is reached remotely over port 37777, the device's proprietary service port. The CVSS vector indicates low privileges are required (PR:L) and no user interaction (UI:N), so any authenticated account on the device is sufficient.
Exploitation
CVE-2020-5735 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and EPSS gives a 30-day exploitation probability of about 0.36 (98th percentile). A public Packet Storm exploit reference exists, though it is tagged as a denial-of-service proof of concept.
What to do
- Apply the vendor firmware updates referenced in Amcrest's advisory and CISA's required action.
- Restrict access to TCP port 37777 to trusted management hosts only; never expose it to the internet.
- Change default and weak credentials and enforce unique, strong passwords on all camera and NVR accounts.
- Segment cameras and NVRs onto an isolated VLAN with no outbound access to the corporate network.
- Monitor vendor advisories and replace devices that no longer receive firmware support.
Detection
- Alert on repeated or malformed traffic to TCP port 37777 from unexpected sources.
- Monitor device logs and availability for unexpected reboots or crashes of cameras and NVRs.
- Watch for new or unusual outbound connections originating from camera/NVR VLANs.
- Track authentication attempts against device management interfaces for brute force or anomalous logins.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-5735 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
18 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157164/Amcrest-Dahua-NVR-Camera-IP2M-841-Denial-Of-Service.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.tenable.com/security/research/tra-2020-20 | Third Party Advisory |
| http://packetstormsecurity.com/files/157164/Amcrest-Dahua-NVR-Camera-IP2M-841-Denial-Of-Service.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.tenable.com/security/research/tra-2020-20 | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5735 | US Government Resource |
Track CVE-2020-5735 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-5735), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.