CVE-2018-11689: Hanwha-Security Hrd-1641 Firmware
Medium severity, CVSS 6.1. EPSS: 1.6% chance of exploitation in the next 30 days.
Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)
Affected products
- Hanwha-Security Hrd-1641 Firmware: up to and including 1.14
- Hanwha-Security Hrd-1642 Firmware: up to and including 1.16
- Hanwha-Security Hrd-440 Firmware: up to and including 1.14
- Hanwha-Security Hrd-442 Firmware: up to and including 1.16
- Hanwha-Security Hrd-443 Firmware: up to and including 1.14
- Hanwha-Security Hrd-840 Firmware: up to and including 1.14
- Hanwha-Security Hrd-841 Firmware: up to and including 1.14
- Hanwha-Security Hrd-842 Firmware: up to and including 1.16
- Hanwha-Security Srd-1694u Firmware: up to and including 1.14
- Samsung Smartviewer: affected versions not specified
Published 2018-06-14. Last modified 2026-06-17.