CVE-2024-35343: Anpviz Ipc-b850 Firmware

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Certain Anpviz products allow unauthenticated users to download arbitrary files from the device's filesystem via a HTTP GET request to the /playback/ URI. This affects IPC-D250, IPC-D260, IPC-B850, IPC-D850, IPC-D350, IPC-D3150, IPC-D4250, IPC-D380, IPC-D880, IPC-D280, IPC-D3180, MC800N, YM500L, YM800N_N2, YMF50B, YM800SV2, YM500L8, and YM200E10 (IP Cameras) firmware v3.2.2.2 and lower and possibly more vendors/models of IP camera.

Affected products

  • Anpviz Ipc-b850 Firmware: up to and including 3.2.2.2
  • Anpviz Ipc-d250 Firmware: up to and including 3.2.2.2
  • Anpviz Ipc-d260 Firmware: up to and including 3.2.2.2
  • Anpviz Ipc-d280 Firmware: up to and including 3.2.2.2
  • Anpviz Ipc-d3150 Firmware: up to and including 3.2.2.2
  • Anpviz Ipc-d3180 Firmware: up to and including 3.2.2.2
  • Anpviz Ipc-d350 Firmware: up to and including 3.2.2.2
  • Anpviz Ipc-d380 Firmware: up to and including 3.2.2.2
  • Anpviz Ipc-d4250 Firmware: up to and including 3.2.2.2
  • Anpviz Ipc-d850 Firmware: up to and including 3.2.2.2
  • Anpviz Ipc-d880 Firmware: up to and including 3.2.2.2
  • Anpviz MC800N Firmware: up to and including 3.2.2.2
  • Anpviz YM200E10 Firmware: up to and including 3.2.2.2
  • Anpviz YM500L8 Firmware: up to and including 3.2.2.2
  • Anpviz YM800N n2 Firmware: up to and including 3.2.2.2
  • Anpviz YM800SV2 Firmware: up to and including 3.2.2.2
  • Anpviz YMF50B Firmware: up to and including 3.2.2.2

Published 2024-05-28. Last modified 2026-06-17.