CVE-2024-52545: Lorex 2k Indoor Wi-Fi Security Camera

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

An unauthenticated attacker can perform an out of bounds heap read in the IQ Service (TCP port 9876). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.

Affected products

  • Lorex 2k Indoor Wi-Fi Security Camera: before 2.800.0000000.8.R.20241111 (fixed in 2.800.0000000.8.R.20241111)
  • Lorextechnology w461asc-E Firmware: before 2.800.0000000.8.r.20241111 (fixed in 2.800.0000000.8.r.20241111)

Published 2024-12-03. Last modified 2026-06-17.