LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-5735: Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-5735 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.

CVE-2020-5735 is a stack-based buffer overflow in Amcrest cameras and Network Video Recorders (NVRs). An unauthenticated remote attacker who can reach the device on port 37777 may crash it and possibly execute code. Because these devices often sit on networks with camera feeds and recording storage, a successful attack can disrupt surveillance, enable further lateral movement, or give an attacker a foothold inside the environment. Confirm exact product coverage and fixed releases against the vendor advisory.

How it works

The weakness is CWE-121: a stack-based buffer overflow. The device accepts input on TCP port 37777 without adequate bounds checking. An attacker who can send crafted data to that port can overwrite memory on the stack. Overwriting the stack can crash the process (denial of service) and, under the right conditions, may allow the attacker to redirect execution and run arbitrary code with the privileges of the vulnerable service. No authentication is required. Specific packet formats and offsets are not detailed here; treat any unauthenticated reachability to port 37777 on Amcrest cameras or NVRs as high risk until the vendor update is applied and verified.

Am I affected? How to find it in your systems

Amcrest cameras and NVRs are commonly deployed for physical security monitoring—on corporate LANs, in branch offices, warehouses, and sometimes on internet-facing segments or via port forwarding. Inventory steps:

Telemetry signs of exploitation attempts include sudden device reboots or service crashes, unexpected traffic spikes or malformed packets destined to port 37777 from external or unusual internal sources, and new outbound connections originating from the camera/NVR after such traffic. Capture and retain packet samples if you observe anomalies; correlate with authentication and management logs on the device if available.

How to remediate

Patch first. Apply the updates published by Amcrest for the affected cameras and NVRs exactly as described in the vendor advisory and follow CISA’s direction to apply updates per vendor instructions. After upgrading:

If you can't patch immediately

Reduce exposure until the vendor update can be installed:

If your data may have been exposed

Actively exploited remote-code-execution flaws on network appliances can lead to full device compromise, credential theft, and lateral movement into broader systems that store or process sensitive data. If you suspect exploitation, isolate affected units, preserve logs and disk images, rotate credentials that may have been present on or accessible from the device, and follow your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data sets to check whether associated accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAmcrest · Cameras and Network Video Recorder (NVR)
WeaknessCWE-121
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities