Impact
Zosi C519M firmware V4.2.8.823C01450BA contains hard‑coded credentials for the RTSP authentication mechanism. Because these credentials cannot be changed, an attacker who can reach the camera over the network can trick the device into accepting the default login. This gives the attacker unlimited, unauthenticated viewing of the video stream, exposing confidential visual data without the owner’s consent. The weakness is an incorrect access control flaw that translates to a loss of confidentiality for the camera’s video feed.
Affected Systems
The vulnerability applies to the Zosi C519M product running firmware version 4.2.8.823C01450BA. No other vendor or product variants are listed in the CNA data.
Risk and Exploitability
The exploit requires only network connectivity to the RTSP port and does not need any prior authentication or privileged access. Because the default credentials are known, the attack can be automated and performed remotely. The CVE’s CVSS score of 7.5 indicates high severity, while the lack of an EPSS score or KEV status does not diminish the ease of exploitation. The simplicity of the attack vector and the availability of the default credentials make it highly likely to be abused in the wild. The impact is direct unauthorized viewing of camera content, which may violate privacy regulations and compromise sensitive operations.
OpenCVE Enrichment