Description
The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes critical data including Wi-Fi credentials and ONVIF service credentials stored in plaintext, enabling further compromise of the network and connected systems.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23188 | The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes critical data including Wi-Fi credentials and ONVIF service credentials stored in plaintext, enabling further compromise of the network and connected systems. |
References
History
Wed, 06 Aug 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aziot
Aziot 2mp Full Hd Smart Wi-fi Cctv Home Security Camera Aziot 2mp Full Hd Smart Wi-fi Cctv Home Security Camera Firmware |
|
| CPEs | cpe:2.3:h:aziot:2mp_full_hd_smart_wi-fi_cctv_home_security_camera:-:*:*:*:*:*:*:* cpe:2.3:o:aziot:2mp_full_hd_smart_wi-fi_cctv_home_security_camera_firmware:1.00.02:*:*:*:*:*:*:* |
|
| Vendors & Products |
Aziot
Aziot 2mp Full Hd Smart Wi-fi Cctv Home Security Camera Aziot 2mp Full Hd Smart Wi-fi Cctv Home Security Camera Firmware |
Wed, 30 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-312 |
|
| Metrics |
cvssV3_1
|
Wed, 30 Jul 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes critical data including Wi-Fi credentials and ONVIF service credentials stored in plaintext, enabling further compromise of the network and connected systems. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-07-30T19:25:51.768Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-50777
Updated: 2025-07-30T19:25:02.368Z
Status : Analyzed
Published: 2025-07-30T19:15:48.920
Modified: 2025-08-06T16:22:46.847
Link: CVE-2025-50777
No data.
OpenCVE Enrichment
No data.
EUVD