{"api_version":"1","generated_at":"2026-07-23T09:41:02+00:00","cve":"CVE-2020-9526","urls":{"html":"https://cve.report/CVE-2020-9526","api":"https://cve.report/api/cve/CVE-2020-9526.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-9526","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-9526"},"summary":{"title":"CVE-2020-9526","description":"CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure flaw that exposes user session data to supernodes in the network, as demonstrated by passively eavesdropping on user video/audio streams, capturing credentials, and compromising devices.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-08-10 16:15:00","updated_at":"2021-07-21 11:39:00"},"problem_types":["CWE-327","CWE-319"],"metrics":[],"references":[{"url":"https://hacked.camera/","name":"https://hacked.camera/","refsource":"MISC","tags":["Third Party Advisory"],"title":"Security cameras vulnerable to hijacking","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://redprocyon.com","name":"https://redprocyon.com","refsource":"MISC","tags":["Third Party Advisory"],"title":"Security cameras vulnerable to hijacking","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-9526","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-9526","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"9526","vulnerable":"1","versionEndIncluding":"3.0.3a","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cs2-network","cpe5":"p2p","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-9526","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure flaw that exposes user session data to supernodes in the network, as demonstrated by passively eavesdropping on user video/audio streams, capturing credentials, and compromising devices."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://hacked.camera/","url":"https://hacked.camera/"},{"url":"https://redprocyon.com","refsource":"MISC","name":"https://redprocyon.com"}]}},"nvd":{"publishedDate":"2020-08-10 16:15:00","lastModifiedDate":"2021-07-21 11:39:00","problem_types":["CWE-327","CWE-319"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.2,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:cs2-network:p2p:*:*:*:*:*:*:*:*","versionEndIncluding":"3.0.3a","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"9526","Ordinal":"169917","Title":"CVE-2020-9526","CVE":"CVE-2020-9526","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"9526","Ordinal":"1","NoteData":"CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure flaw that exposes user session data to supernodes in the network, as demonstrated by passively eavesdropping on user video/audio streams, capturing credentials, and compromising devices.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"9526","Ordinal":"2","NoteData":"2020-08-10","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"9526","Ordinal":"3","NoteData":"2020-08-10","Type":"Other","Title":"Modified"}]}}}