Impact
The flaw lies in the lack of proper validation of the certificate presented by the device management server, allowing a network‑adjacent attacker to exploit the camera without requiring user interaction and enabling arbitrary code execution in the context of root.
Affected Systems
Lorex 2K Indoor Wi‑Fi Security Camera; version information is not specified in the advisory 7.5, indicating a high severity vulnerability. The exploit probability (EPSS) is 0.00096 (approximately 0.096%) and the vulnerability is not listed in the CISA KEV catalog. Because the certificate is not validated, a local network attacker who can reach the device’s management interface can launch the attack; no user interaction is required, which lowers the effort needed to exploit the flaw. When combined with other weaknesses, the attacker can gain root‑level code execution.
Risk and Exploitability
The CVSS v3.1 score of 7.5 classifies this flaw as high severity, indicating a potentially large impact if exploited. The EPSS value indicates a very low probability of real‑world exploitation (<1%), and the vulnerability is not currently listed in CISA’s KEV catalog. The flaw is a certificate validation failure (CWE‑295) that can be exploited by any attacker who can reach an affected camera’s device‑management network interface, such as on a local or adjacent network segment. Since user interaction is not required, an attacker can trigger the flaw remotely from within that network. If combined with other local exploits, the attacker could execute arbitrary code with root privileges.
OpenCVE Enrichment