Vulnerability record · CVE-2023-3959 · published 8 November 2023
CVE-2023-3959: Zavio IP cameras stack overflow in XML request handling
Zavio · Cf7500 Firmware
Multiple Zavio IP camera models running firmware M2.1.6.05 fail to validate buffer sizes when processing XML elements in incoming network requests, causing stack-based buffer overflows (CWE-121/CWE-787). Successful exploitation may allow remote code execution on the camera. The flaw affects eleven camera/firmware product entries and carries a critical CVSS score of 9.8.
Description
Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While processing XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network-reachable, unauthenticated remote code execution and a high EPSS percentile make this a top remediation priority despite no confirmed in-the-wild exploitation.
What it is
Multiple Zavio IP camera models running firmware M2.1.6.05 fail to validate buffer sizes when processing XML elements in incoming network requests, causing stack-based buffer overflows (CWE-121/CWE-787). Successful exploitation may allow remote code execution on the camera. The flaw affects eleven camera/firmware product entries and carries a critical CVSS score of 9.8.
Impact
An unauthenticated remote attacker can corrupt stack memory and potentially execute arbitrary code on the device, gaining full control of the camera. That enables data theft, use of the camera as a network pivot point, or disruption of surveillance.
Attack surface
Reached over the network via incoming requests containing crafted XML elements, per the CVSS vector AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is required. Any camera interface that parses XML from the network is a candidate entry point.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at roughly 0.49 (98.8th percentile), indicating substantial predicted exploitation likelihood, but the record contains no public exploit or in-the-wild confirmation.
What to do
- Apply the vendor firmware update for the affected Zavio camera models; if no fixed firmware exists, isolate or replace the devices.
- Place cameras on a dedicated VLAN with strict firewall rules so only trusted management hosts can reach them, never exposing them to the internet.
- Disable or block unnecessary services and XML-processing endpoints on the cameras where the device configuration allows it.
- Monitor vendor and CISA ICS advisory ICSA-23-304-03 for updated guidance and fixed firmware versions.
Detection
- Monitor camera network traffic for oversized or malformed XML payloads and unexpected crash/reboot patterns in device logs.
- Alert on abnormal outbound connections or new listening behavior from camera IP addresses, which may indicate post-exploitation activity.
- Track repeated connection attempts or fuzzing-like request bursts against camera management interfaces from untrusted hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-03 | Third Party AdvisoryUS Government Resource |
| https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-03 | Third Party AdvisoryUS Government Resource |
Track CVE-2023-3959 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-3959), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.