Uniqcli Security
← Advisories
HighHanwha VisionDecember 26, 2025

Hard-coded Cryptographic Key in Hanwha Wisenet Device Manager (CVE-2025-52601)

NDAA Section 889: Hanwha Vision is a South Korean manufacturer and is not on the NDAA Section 889 covered list; it is frequently specified as a TAA/NDAA-compliant alternative to prohibited Chinese-origin brands. This is a routine firmware/credential-hygiene issue that does not change Hanwha's compliance status. This brand is a covered entity — replacing it, not just patching it, is the compliant path. See compliant replacements →

Summary

Hanwha's Wisenet Device Manager ships a hard-coded encryption key, so an attacker who can read the stored configuration is able to decrypt the shared default credentials used to manage the camera fleet. Recovering those credentials hands over administrative access to large numbers of devices at once, turning a local file-read into estate-wide control. The flaw was disclosed by Nozomi Networks Labs alongside four other Wisenet findings and patched in coordination with Hanwha's PSIRT.

Affected products

Wisenet Device Manager (WDM) prior to v2.9.3.1Numerous Wisenet camera series (KNB, KND, KNO, KNP, PNM, QND, QNE, QNF, QNO, QNP, QNV, TNB, TNV, XNB, XND, XNF, XNO, XNP, XNV, XNZ) with firmware prior to model-specific patches

Impact

Decryption of default management credentials enabling unauthorized administrative access across a Wisenet deployment, including configuration tampering, stream interception, and disabling of cameras. CVSS is scored 7.8 High under v3.1 and 6.3 Medium under the newer v4.0 metric; the high confidentiality/integrity impact is what drives the rating.

Remediation

Update Wisenet Device Manager to v2.9.3.1 or later and apply the model-specific patched camera firmware (release ranges 2.10.03 through 2.24.00 depending on model; reference Hanwha's December 2025 vulnerability report). Rotate any credentials that may have been managed through an affected WDM instance, and restrict WDM host access to trusted administrators only. Uniqcli Security can pull a model-by-model firmware inventory of your Wisenet estate, push the staged updates, and rotate credentials so a single recovered key no longer unlocks the fleet.

Sources

Want us to handle it?

We patch, harden or replace affected devices and document the closeout.

Request a fleet scan
Stay ahead of it

Scan your fleet for vulnerable or banned devices.

Tell us what you need secured. We'll confirm compliance, design the system, and quote it — no payment up front.