Home

Description

An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` parameter in the `/uapi-cgi/viewer/Param.cgi` script. This has been confirmed on the EFD-2130 camera running firmware version 1.12.0.19.

PUBLISHED Reserved 2025-10-29 | Published 2025-11-03 | Updated 2025-11-03 | Assigner BLSOPS




CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

Default status
unaffected

1.12.0.19
affected

References

blog.blacklanternsecurity.com/...25-12463-98-unauthenticated

cve.org (CVE-2025-12463)

nvd.nist.gov (CVE-2025-12463)

Download JSON