CVE-2024-52544: Lorex 2k Indoor Wi-Fi Security Camera

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

An unauthenticated attacker can trigger a stack based buffer overflow in the DP Service (TCP port 3500). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.

Affected products

  • Lorex 2k Indoor Wi-Fi Security Camera: before 2.800.0000000.8.R.20241111 (fixed in 2.800.0000000.8.R.20241111)
  • Lorextechnology w461asc-E Firmware: before 2.800.0000000.8.r.20241111 (fixed in 2.800.0000000.8.r.20241111)

Published 2024-12-03. Last modified 2026-06-17.