Default Credential Flaw in 70mai X200 HTTP Web Server
CVE-2025-11943
Key Information:
Badges
What is CVE-2025-11943?
A vulnerability has been identified in the 70mai X200 dashboard camera, specifically related to its HTTP Web Server functionality. This issue allows attackers to exploit the system by leveraging default credentials to gain unauthorized access remotely. Despite the public disclosure of the exploit, the vendor has not communicated on this matter after being notified of the vulnerability. Users of the affected product should prioritize security measures to mitigate potential risks.
Affected Version(s)
X200 20251010
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved