Critical IDIS IP Camera Vulnerability Allows Full Computer Compromise with One-Click Exploit
ID: 76bfaa84-2b43-522e-b7b0-3d4cfbce49a2
STIX ID: report--76bfaa84-2b43-522e-b7b0-3d4cfbce49a2
Feed Name: GBHackers
Threat Score
A critical RCE vulnerability in IDIS Cloud Manager's Windows ICM Viewer (CVE-2025-12556, CVSSv4 8.7) lets a malicious webpage reach a local service (CWGService.exe) via ws://localhost:16140, send an encrypted command using a hard-coded key, and inject Chromium command-line flags into WCMViewer.exe to execute arbitrary code; IDIS and CISA recommend immediate upgrade to version 1.7.1 or uninstalling the viewer.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
