← Vulnerability feed

Vulnerability record · CVE-2023-3959 · published 8 November 2023

CVE-2023-3959: Zavio IP cameras stack overflow in XML request handling

Zavio · Cf7500 Firmware

Multiple Zavio IP camera models running firmware M2.1.6.05 fail to validate buffer sizes when processing XML elements in incoming network requests, causing stack-based buffer overflows (CWE-121/CWE-787). Successful exploitation may allow remote code execution on the camera. The flaw affects eleven camera/firmware product entries and carries a critical CVSS score of 9.8.

9.8 CVSS 3.1 Critical EPSS 49% · top 1.2% CWE-121 · Stack-based buffer overflowCWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerable to multiple instances of stack-based overflows. While processing XML elements from incoming network requests, the product does not sufficiently check or validate allocated buffer size. This may lead to remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network-reachable, unauthenticated remote code execution and a high EPSS percentile make this a top remediation priority despite no confirmed in-the-wild exploitation.

What it is

Multiple Zavio IP camera models running firmware M2.1.6.05 fail to validate buffer sizes when processing XML elements in incoming network requests, causing stack-based buffer overflows (CWE-121/CWE-787). Successful exploitation may allow remote code execution on the camera. The flaw affects eleven camera/firmware product entries and carries a critical CVSS score of 9.8.

Impact

An unauthenticated remote attacker can corrupt stack memory and potentially execute arbitrary code on the device, gaining full control of the camera. That enables data theft, use of the camera as a network pivot point, or disruption of surveillance.

Attack surface

Reached over the network via incoming requests containing crafted XML elements, per the CVSS vector AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is required. Any camera interface that parses XML from the network is a candidate entry point.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at roughly 0.49 (98.8th percentile), indicating substantial predicted exploitation likelihood, but the record contains no public exploit or in-the-wild confirmation.

What to do

  • Apply the vendor firmware update for the affected Zavio camera models; if no fixed firmware exists, isolate or replace the devices.
  • Place cameras on a dedicated VLAN with strict firewall rules so only trusted management hosts can reach them, never exposing them to the internet.
  • Disable or block unnecessary services and XML-processing endpoints on the cameras where the device configuration allows it.
  • Monitor vendor and CISA ICS advisory ICSA-23-304-03 for updated guidance and fixed firmware versions.

Detection

  • Monitor camera network traffic for oversized or malformed XML payloads and unexpected crash/reboot patterns in device logs.
  • Alert on abnormal outbound connections or new listening behavior from camera IP addresses, which may indicate post-exploitation activity.
  • Track repeated connection attempts or fuzzing-like request bursts against camera management interfaces from untrusted hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-03 Third Party AdvisoryUS Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-03 Third Party AdvisoryUS Government Resource

Track CVE-2023-3959 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-4249Zavio cf7500 firmware stack-based buffer overflow vulnerabilityZavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 has a comman…EPSS 13%9.8CVE-2023-45225Zavio cf7500 firmware stack-based buffer overflow vulnerabilityZavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras  with firmware version M2.1.6.05 are vulnera…EPSS 1.3%9.8CVE-2023-43755Zavio cf7500 firmware stack-based buffer overflow vulnerabilityZavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerab…EPSS 1.3%9.8CVE-2023-39435Zavio cf7500 firmware stack-based buffer overflow vulnerabilityZavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vulnerab…EPSS 1.2%8.8CVE-2026-7273Zyxel gs1900-8 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-base…KEVEPSS 2.5%8.1CVE-2021-27137DD-WRT UPnP M-SEARCH stack buffer overflowDD-WRT before 45724 contains an unsafe strcpy in the UPnP SSDP handling code (ssdp_msearch), reachable via an M-SEARCH request, that overflows a fixe…KEVEPSS 4.0%analysed9.3CVE-2025-53521F5 BIG-IP APM stack buffer overflow allows remote code executionA stack-based buffer overflow (CWE-121) exists in F5 BIG-IP Access Policy Manager when an APM access policy is configured on a virtual server. Specif…KEVEPSS 2.3%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed

Source: NIST National Vulnerability Database (record CVE-2023-3959), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.