potentially enabling an attacker to connect to backend services. The
attacker would then be able to gain unauthorized access to available
cameras, enabling the viewing of live feeds or modification of settings.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Ubia did not respond to CISA's attempts to coordinate. Users of Ubia Cameras are encouraged to reach out out to Ubia for more information.
Thu, 06 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to backend services. The attacker would then be able to gain unauthorized access to available cameras, enabling the viewing of live feeds or modification of settings. | |
| Title | Ubia Ubox | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-11-06T22:53:41.808Z
Reserved: 2025-11-03T15:33:59.314Z
Link: CVE-2025-12636
No data.
Status : Received
Published: 2025-11-06T23:15:35.693
Modified: 2025-11-06T23:15:35.693
Link: CVE-2025-12636
No data.
OpenCVE Enrichment
No data.