Skip to main content

CVE-2025-8075: Hanwhavision Xno-8082r Firmware XSS Flaw

CVE-2025-8075 is a cross-site scripting vulnerability in Hanwhavision Xno-8082r Firmware caused by inadequate XML validation. Attackers can exploit this flaw to execute malicious scripts in user browsers. This article covers technical details, affected versions, security impact, and available mitigation strategies.

Published:

CVE-2025-8075 Overview

CVE-2025-8075 is a Cross-Site Scripting (XSS) vulnerability affecting a broad range of Hanwha Vision network camera firmware. The flaw stems from inadequate validation of incoming XML format request messages, which allows an attacker to inject script content that executes in the context of a user's browser. Nozomi Networks Labs, a security research team focused on Industrial Control Systems (ICS) and OT/IoT security, discovered and reported the issue. Hanwha Vision has released patch firmware for affected models.

Critical Impact

An attacker with low-level authenticated access can inject malicious script into XML requests, executing code in the browser of any user viewing the affected camera interface. This can compromise operator sessions in physical security and OT environments.

Affected Products

  • Hanwha Vision XNO, XNV, XND, XNB series network cameras (multiple models including XNO-8082R, XNV-8082R, XND-8082RF)
  • Hanwha Vision PNM multi-sensor camera series (including PNM-9084QZ1, PNM-9322VQP, PNM-9000VD)
  • Hanwha Vision QNV, QNO, QND, QNE, QNF, QNP, TNV, TNB, KNO, KND, KNP, KNB series cameras

Discovery Timeline

  • Discovered by Nozomi Networks Labs
  • 2025-12-26 - CVE-2025-8075 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-8075

Vulnerability Analysis

The vulnerability is a stored or reflected Cross-Site Scripting flaw rooted in insufficient input validation of XML-formatted request messages processed by the camera's web management interface. When the camera parses incoming XML requests, it fails to sanitize or encode script-bearing content before rendering that data back to authenticated users through the administrative UI. An attacker who can submit crafted XML to the device can therefore cause arbitrary JavaScript to run in the context of another user's browser session.

Because these cameras are typically deployed on physical security networks in enterprise, industrial, and critical infrastructure environments, a successful XSS attack can lead to hijacked operator sessions, stolen credentials, modified device configurations, and pivoting into adjacent OT/IoT segments. The vulnerability requires low-privilege authenticated access over the network but no user interaction beyond an operator viewing the affected interface element.

Root Cause

The root cause is inadequate input validation combined with improper output encoding of user-controllable XML request fields (CWE-20: Improper Input Validation and CWE-79: Improper Neutralization of Input During Web Page Generation). The web application accepts XML payloads and reflects parsed values into HTML responses without neutralizing script constructs.

Attack Vector

An authenticated attacker sends a crafted XML request to the camera's management endpoint. Injected script content is stored or reflected back to the browser of an administrator or operator, where it executes with the privileges of that user's session. From there, the attacker can perform actions on behalf of the victim, exfiltrate session tokens, or alter camera settings across the fleet.

// Example exploitation pattern (conceptual - no verified PoC available)
// Attacker submits XML containing unescaped script content to a device endpoint
// that later renders the value into an administrator-facing page.

Detection Methods for CVE-2025-8075

Indicators of Compromise

  • Unexpected XML request payloads to camera management endpoints containing HTML or JavaScript control characters such as <script>, onerror=, or javascript:.
  • Anomalous outbound connections from operator workstations that recently viewed the affected camera web interface.
  • Unauthorized configuration changes or new administrative accounts on Hanwha Vision cameras.

Detection Strategies

  • Inspect HTTP/HTTPS traffic to camera management interfaces for XML request bodies containing script tags or encoded script payloads.
  • Correlate camera administrative logins with subsequent unusual browser activity on the same workstation, such as unexpected script execution or redirects.
  • Monitor firmware and configuration integrity on Hanwha Vision cameras to detect unauthorized modifications.

Monitoring Recommendations

  • Enable web application firewall (WAF) or network intrusion detection signatures for XSS patterns targeting camera XML endpoints.
  • Log and centrally review all authentication events, configuration changes, and API interactions with Hanwha Vision devices.
  • Segment camera VLANs and log cross-segment traffic to detect lateral movement following a compromised operator session.

How to Mitigate CVE-2025-8075

Immediate Actions Required

  • Apply the patched firmware published by Hanwha Vision to every affected camera model as identified in the vendor advisory.
  • Restrict access to camera management interfaces to a dedicated management network and trusted administrator workstations only.
  • Rotate credentials for all camera administrator and operator accounts, and remove any accounts that are unused or unnecessary.

Patch Information

Hanwha Vision has released firmware updates addressing CVE-2025-8075. Refer to the vendor advisory for exact firmware versions per model: Hanwha Vision Camera Vulnerability Report CVE-2025-5259852601.

Workarounds

  • Place cameras behind a reverse proxy or WAF configured to filter XML payloads containing script content until firmware can be updated.
  • Disable or restrict remote access to camera web interfaces; require VPN or jump-host access for administration.
  • Enforce browser-side protections such as Content Security Policy at the proxy layer and use dedicated, hardened workstations for camera management.
bash
# Example: restrict camera management access via firewall to a management subnet
iptables -A INPUT -p tcp --dport 443 -s 10.10.50.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 443 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.