logo

Critical Vulnerability in Multiple India-Based CCTV Cameras Let Attackers Video and Account Credentials

ID: 50774728-a47a-5b99-9a60-82ba3a62de48

STIX ID: report--50774728-a47a-5b99-9a60-82ba3a62de48

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-11

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical missing-authentication vulnerability (CVE-2025-13607, CWE-306) affecting multiple India-based CCTV manufacturers — confirmed in D-Link DCS-F5614-L1 (firmware v1.03.038 and earlier) and reported as impacting other vendors — was disclosed and highlighted by CISA (ICSA-25-343-03). The flaw (CVSS v4 9.3) allows unauthenticated remote access to camera configuration and administrative credentials, posing a risk to surveillance infrastructure; vendors are urged to apply available patches, isolate cameras from the internet, and restrict access via firewalls or VPNs, while CISA notes no active public exploitation reported at the time of the advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.