Historical intelligence backfill. This assessment covers reporting originally published on 2026-01-28 and was added to the RWP archive on 2026-09-07.

Daily Top · OT

Hanwha Wisenet: five mediums, a hard-coded WDM password, and a camera fleet that sits on the OT VLAN anyway

Nozomi, 28 January 2026 — QNV-C8012 firmware v2.22.00_20240909_R188 and Wisenet Device Manager 2.9.2.0. CVE-2025-52598–52601 and CVE-2025-8075. Not a worm. Still a plant-floor camera problem.

RWP Ventures · 2026-09-07 · event 2026-01-28 · 2 min read · priority 7.0

Bottom line up front

CONFIRMED Nozomi Labs, 28 January 2026 — five medium-severity issues on Hanwha Vision QNV-C8012 (firmware v2.22.00_20240909_R188) and Wisenet Device Manager v2.9.2.0, confirmed via Hanwha S-CERT. CVE-2025-52598 CWE-295 TLS validation (6.3); CVE-2025-52599 CWE-732 permissions (6.3); CVE-2025-52600 CWE-602 client-side enforcement (5.2); CVE-2025-52601 CWE-259 hard-coded password in WDM (6.3); CVE-2025-8075 XSS in CloudConnector (5.8). Combined, they support reading sensitive data, changing device/fleet settings, and using the camera as a foothold. Nozomi did not claim active exploitation. Separate June 2025 Hanwha statement on firmware decryption keys for older Wisenet families is a different bug class — do not merge. Process impact: UNKNOWN. Camera-as-recon is the industrial relevance (see Nozomi's later IP-camera warfare note as context, not as this CVE set).

Historical backfill of 28 January 2026 reporting; added 7 September 2026.

What happened

A camera plus its Windows fleet manager. Hard-coded WDM secret and broken TLS on the camera are the two that survive a "medium CVSS, ignore" filter.

Why it mattered

Plant cameras share VLANs with controllers more often than architecture diagrams admit. Medium on a camera is still a pivot.

Who / what was affected

QNV-C8012 on the named firmware; WDM 2.9.2.0. Check Hanwha S-CERT for sibling SKUs.

Technical context

Patch camera firmware and WDM. Rotate any password that WDM baked in. Segment cameras off the control LAN. Fix TLS so management is not MITM'd.

Exploitation / threat status at the time

CONFIRMED five CVEs, vendor acknowledged.

UNKNOWN in-the-wild.

What defenders should have done

  1. WDM upgrade; do not leave 2.9.2.0 on engineering laptops.
  2. Camera firmware to S-CERT's fixed build.
  3. VLAN cameras.

RWP assessment

Confidence: High on the CVE table. Do not inflate to "Hanwha is owned."

Defensive actions

  1. Physical-security VLAN as OT-adjacent, not "IT only."
  2. Inventory WDM installs — they are admin of the fleet.
  3. Keep the 2025 key-disclosure statement on a different ticket.

Sources

  1. Nozomi Networks — Five new flaws in Hanwha Wisenet cameras
  2. Mallen Services — CVE summary for QNV-C8012 and WDM
  3. Hanwha Vision S-CERT — Firmware decryption-key disclosure statement (legacy Wisenet families)