Arbitrary Command Injection Vulnerability in Diviotec IP Cameras
CVE-2025-5113

8.6HIGH

Key Information:

Vendor

Diviotec

Vendor
CVE Published:
2 June 2025

What is CVE-2025-5113?

The Diviotec Professional Series IP Cameras feature a web interface that contains a vulnerability allowing for arbitrary command injection. Attackers can exploit this weakness to execute unauthorized commands on the device. Furthermore, the use of hardcoded passwords poses an additional security risk, potentially allowing unauthorized access to the cameras. This combination of vulnerabilities endangers the integrity and privacy of the users relying on these surveillance devices.

Affected Version(s)

nbf232p 0 <= 2.0170.3030

nbf233p 0 <= 2.0170.3030

nbr222p 0 <= 2.0170.3030

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ONEKEY Research Labs
.