# CVE-2024-41885

## Summary

- **CVE ID:** CVE-2024-41885
- **Severity:** MEDIUM
- **CVSS Score:** 5.6 (CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-547
- **Published:** Dec 24, 2024
- **Last Modified:** Mar 13, 2026

## Description

Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. The seed string for the encrypt key was hardcoding. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

## Affected Products

- Hanwha Vision Co., Ltd. — XRN-420S (5.01.62 and prior versions)

## References

- [CNA](https://www.hanwhavision.com/wp-content/uploads/2024/12/NVR-Vulnerability-Report-CVE-2024-4188241887.pdf)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.18%
- **EPSS Percentile:** 7.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._