CVE-2014-1201: Lorex Technology Edge+ LH320 Firmware
High severity, CVSS 10.0. EPSS: 29.5% chance of exploitation in the next 30 days.
Buffer overflow in the INetViewX ActiveX control in the Lorex Edge LH310 and Edge+ LH320 series with firmware 7-35-28-1B26E, Edge2 LH330 series with firmware 11.17.38-33_1D97A, and Edge3 LH340 series with firmware 11.19.85_1FE3A allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the HTTP_PORT parameter.
Affected products
- Lorex Technology Edge+ LH320 Firmware: version 7-35-28-1b26e only
- Lorex Technology EDGE2 LH330 Firmware: version 11.17.38-33_1d97a only
- Lorex Technology EDGE3 LH340 Firmware: version 11.19.85_1fe3a only
- Lorex Technology Edge LH310 Firmware: version 7-35-28-1b26e only
- Lorextechnology Edge
- Lorextechnology Edge+
- Lorextechnology EDGE2
- Lorextechnology EDGE3
Published 2014-01-15. Last modified 2026-06-17.