Cleartext Storage Vulnerability in FNKvision FNK-GU2 Wireless IP Camera
CVE-2025-7215

1LOW

Key Information:

Vendor

Fnkvision

Status
Vendor
CVE Published:
9 July 2025

What is CVE-2025-7215?

A vulnerability has been identified in the FNKvision FNK-GU2 Wireless IP Camera that allows for the cleartext storage of sensitive information within the device's configuration file, specifically /rom/wpa_supplicant.conf. This issue poses a significant risk as it can be exploited through physical access to the device, thereby exposing critical data. The complexity associated with launching an exploit remains relatively high, although the public disclosure of the vulnerability increases the likelihood of malicious attempts. Users are urged to evaluate their device security measures in light of this vulnerability to protect sensitive data from potential unauthorized access.

Affected Version(s)

FNK-GU2 40.1.0

FNK-GU2 40.1.1

FNK-GU2 40.1.2

References

CVSS V4

Score:
1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xHasta (VulDB User)
.
CVE-2025-7215 : Cleartext Storage Vulnerability in FNKvision FNK-GU2 Wireless IP Camera