logo

Critical IDIS IP Camera Vulnerability Allows Full Computer Compromise with One-Click Exploit

ID: 76bfaa84-2b43-522e-b7b0-3d4cfbce49a2

STIX ID: report--76bfaa84-2b43-522e-b7b0-3d4cfbce49a2

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-28

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A critical RCE vulnerability in IDIS Cloud Manager's Windows ICM Viewer (CVE-2025-12556, CVSSv4 8.7) lets a malicious webpage reach a local service (CWGService.exe) via ws://localhost:16140, send an encrypted command using a hard-coded key, and inject Chromium command-line flags into WCMViewer.exe to execute arbitrary code; IDIS and CISA recommend immediate upgrade to version 1.7.1 or uninstalling the viewer.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.