CVE-2026-4910Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus up to 1.3.44. Affected is an unknown function of the file /RemoteFormat.do of the component Endpoint. Such manipulation of the argument State leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-27: 4Technical Details · 2026-03-27: 103-27
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Full discourse4 posts
  • White Rabbitx@TheRabbitPy
    Disclosure

    📹 Streamax Crocus camera RCE (CVE-2026-4910) Shenzhen Ruiming IoT camera vuln in unknown function → remote code exec. Surveillance cams = pivot paradise. Swap for secure alternatives. https://nvd.nist.gov/vuln/detail/CVE-2026-4910 #IoT #CVE

    Post summary

    This tweet announces CVE‑2026‑4910, highlighting remote code execution in Streamax Crocus cameras, and directs readers to the NVD entry for more information.

    00000104
    492 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4910 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4910 #CVE-2026-4910 #CVE #High #CyberSecurity #InfoSec https://t.co/8tnhs8z5nV

    Post summary

    The tweet merely announces CVE-2026-4910 with a 7.3 severity rating and high risk, noting it affects multiple products, but it provides no further technical details, fixes, or exploitation information.

    0000033
    123 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4910 A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus bis 1.3.44. Affected is an unknown function of the file /RemoteFormat.do of th… https://www.cve.org/CVERecord?id=CVE-2026-4910

    Post summary

    The post merely notes that CVE-2026-4910 was detected in Streamax Crocus bis 1.3.44, offering no further technical, exploit, or remediation details.

    0000096
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4910 - Shenzhen Ruiming Technology Streamax Crocus Endpoint http://RemoteFormat.do sql injection Intel Report: https://ift.tt/DsuBNXT

    Post summary

    The alert announces CVE-2026-4910 as a SQL injection vulnerability affecting the Streamax Crocus Endpoint, providing a reference to an intel report for further details.

    0000037
    284 followersView on X

Explore more