Description
Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can use the unchangeable default credentials to access the RTSP video stream, resulting in unauthorized viewing of camera footage.
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Zosi C519M firmware V4.2.8.823C01450BA contains hard‑coded credentials for the RTSP authentication mechanism. Because these credentials cannot be changed, an attacker who can reach the camera over the network can trick the device into accepting the default login. This gives the attacker unlimited, unauthenticated viewing of the video stream, exposing confidential visual data without the owner’s consent. The weakness is an incorrect access control flaw that translates to a loss of confidentiality for the camera’s video feed.

Affected Systems

The vulnerability applies to the Zosi C519M product running firmware version 4.2.8.823C01450BA. No other vendor or product variants are listed in the CNA data.

Risk and Exploitability

The exploit requires only network connectivity to the RTSP port and does not need any prior authentication or privileged access. Because the default credentials are known, the attack can be automated and performed remotely. The CVE’s CVSS score of 7.5 indicates high severity, while the lack of an EPSS score or KEV status does not diminish the ease of exploitation. The simplicity of the attack vector and the availability of the default credentials make it highly likely to be abused in the wild. The impact is direct unauthorized viewing of camera content, which may violate privacy regulations and compromise sensitive operations.

Generated by OpenCVE AI on August 5, 2026 at 22:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a firmware update that removes the hard‑coded RTSP credentials or introduces a changeable credential mechanism.
  • If an update is unavailable, configure the device to use a unique, non‑default username and password for RTSP access via the manufacturer’s configuration interface.
  • Implement network segmentation or firewall rules to restrict access to the RTSP port only to trusted hosts or IP ranges.
  • Disable RTSP service entirely if it is not required for operation.

Generated by OpenCVE AI on August 5, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Zositech
Zositech zosi C519m
Vendors & Products Zositech
Zositech zosi C519m

Wed, 05 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Hardcoded RTSP Credentials Allow Remote Camera Access in Zosi C519M

Wed, 05 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Zosi RTSP Hardcoded Credentials Leak Camera Footage
Weaknesses CWE-798

Wed, 05 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Title Zosi RTSP Hardcoded Credentials Leak Camera Footage
Weaknesses CWE-284
CWE-798

Wed, 05 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can use the unchangeable default credentials to access the RTSP video stream, resulting in unauthorized viewing of camera footage.
References

Subscriptions

Zositech Zosi C519m
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-05T19:30:02.150Z

Reserved: 2026-01-09T00:00:00.000Z

Link: CVE-2025-70962

cve-icon Vulnrichment

Updated: 2026-08-05T19:29:38.070Z

cve-icon NVD

Status : Received

Published: 2026-08-05T14:16:58.390

Modified: 2026-08-05T20:17:04.247

Link: CVE-2025-70962

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T11:13:22Z

Weaknesses