CVE-2026-32683 Details
Description
Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmission risk. Attackers can exploit this by eavesdropping on network requests to obtain data.Users are advised to upgrade the app to the latest version and enable the video encryption feature.
A data interception vulnerability exists in some EZVIZ and Hikvision products that use older cloud function modules with legacy API interfaces. This vulnerability allows attackers to eavesdrop on network requests and obtain data, posing a risk during data transmission. Affected products include the EZVIZ App on iOS versions prior to 7.3.1 and Android versions prior to 7.3.0.0210, as well as the Hik-Connect App versions below 6.11.80.
Users are advised to upgrade to the latest version of the EZVIZ App or Hik-Connect App and enable the video encryption feature. The latest version can be downloaded from major app stores or through the in-app update module.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | CISA-ADP |
Affected Products
No affected product data is available for this CVE.
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 25, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | CVE Modified | CISA-ADP |
| May 9, 2026 | New CVE Received | [email protected] |