Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NHIGH: 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
v1.1.124
affected
Description
The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to backend services. The attacker would then be able to gain unauthorized access to available cameras, enabling the viewing of live feeds or modification of settings.
Problem types
Product status
v1.1.124
Credits
Milos C. reported this vulnerability to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-310-02
github.com/...p/csaf_files/OT/white/2025/icsa-25-310-02.json
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.