CVE-2017-14262: Samsung Srn 1000 Firmware
High severity, CVSS 8.1. EPSS: 4.4% chance of exploitation in the next 30 days.
On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUserPasswd parameter.
Affected products
- Samsung Srn 1000 Firmware: affected versions not specified
- Samsung Srn 1670d Firmware: affected versions not specified
- Samsung Srn 470d Firmware: affected versions not specified
- Samsung Srn 472s Firmware: affected versions not specified
Published 2017-09-11. Last modified 2026-06-17.