Description
A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of the file /onvif/device_service of the component ONVIF Device Management Service. Executing manipulation of the argument FactoryDefault with the input Hard can lead to improper access controls. The attack requires access to the local network. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2025-12-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 18 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Shenzhenningyuandatechnology
Shenzhenningyuandatechnology tc155
Shenzhenningyuandatechnology tc155 Firmware
CPEs cpe:2.3:h:shenzhenningyuandatechnology:tc155:-:*:*:*:*:*:*:*
cpe:2.3:o:shenzhenningyuandatechnology:tc155_firmware:57.0.2.0:*:*:*:*:*:*:*
Vendors & Products Shenzhenningyuandatechnology
Shenzhenningyuandatechnology tc155
Shenzhenningyuandatechnology tc155 Firmware

Tue, 16 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Ningyuanda
Ningyuanda tc155
Vendors & Products Ningyuanda
Ningyuanda tc155

Tue, 16 Dec 2025 03:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of the file /onvif/device_service of the component ONVIF Device Management Service. Executing manipulation of the argument FactoryDefault with the input Hard can lead to improper access controls. The attack requires access to the local network. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title Ningyuanda TC155 ONVIF Device Management Service device_service access control
Weaknesses CWE-266
CWE-284
References
Metrics cvssV2_0

{'score': 4.8, 'vector': 'AV:A/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Ningyuanda Tc155
Shenzhenningyuandatechnology Tc155 Tc155 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-12-16T21:01:07.215Z

Reserved: 2025-12-15T20:39:17.819Z

Link: CVE-2025-14748

cve-icon Vulnrichment

Updated: 2025-12-16T21:01:04.032Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-16T03:15:57.660

Modified: 2025-12-18T21:24:06.597

Link: CVE-2025-14748

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-16T20:45:21Z

Weaknesses