logo

Probing the Xiongmai/HiSilicon SoC Vulnerability

ID: e6c12604-670a-5439-8e2a-404b554dbab9

STIX ID: report--e6c12604-670a-5439-8e2a-404b554dbab9

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2020-02-07

Date Updated: 2026-04-27

...
...

This report details a critical firmware backdoor in HiSilicon-based IP video devices from Xiongmai that activates a telnet service via a "secret knock" on TCP/9530; the backdoor uses a hard-coded pre-shared key recoverable from firmware, and further weaknesses in the devices' PRNGs make challenge-response authentication predictable. Censys scanning found thousands of exposed devices globally (notably ~9,362 speaking the HiSilicon protocol), commonly with RTSP and HTTP also accessible, increasing risk of remote compromise, surveillance, or incorporation into botnets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.