LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when a specially crafted QR code is presented to the camera.

Project Subscriptions

Vendors Products
Ptz Dual Band Camera Subscribe
Ptz Dual Band Camera Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2025-7219 LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when a specially crafted QR code is presented to the camera.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00112}

epss

{'score': 0.00154}


Mon, 07 Jul 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Lsc
Lsc ptz Dual Band Camera
Lsc ptz Dual Band Camera Firmware
CPEs cpe:2.3:h:lsc:ptz_dual_band_camera:-:*:*:*:*:*:*:*
cpe:2.3:o:lsc:ptz_dual_band_camera_firmware:7.6.32:*:*:*:*:*:*:*
Vendors & Products Lsc
Lsc ptz Dual Band Camera
Lsc ptz Dual Band Camera Firmware

Fri, 21 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 16:00:00 +0000

Type Values Removed Values Added
Description LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when a specially crafted QR code is presented to the camera.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-21T20:44:34.654Z

Reserved: 2025-02-07T00:00:00.000Z

Link: CVE-2025-25680

cve-icon Vulnrichment

Updated: 2025-03-21T20:44:29.127Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-11T16:15:17.413

Modified: 2025-07-07T18:16:05.933

Link: CVE-2025-25680

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses