Description
A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of the file /onvif/device_service of the component ONVIF PTZ Control Interface. The manipulation leads to improper access controls. The attack requires being on the local network. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Problem types
Incorrect Privilege Assignment
Product status
Timeline
| 2025-12-15: | Advisory disclosed |
| 2025-12-15: | VulDB entry created |
| 2025-12-15: | VulDB entry last update |
Credits
keroomi (VulDB User)
References
vuldb.com/?id.336522 (VDB-336522 | Ningyuanda TC155 ONVIF PTZ Control device_service access control)
vuldb.com/?ctiid.336522 (VDB-336522 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.707198 (Submit #707198 | Shenzhen Ningyuanda Technology Co., Ltd. TC155 IP Camera Firmware version: 57.0.2.0 Unauthenticated ONVIF PTZ Full Remote Camera Control)
github.com/...s/blob/main/TC155-Unauth-PTZ-Remote-Control.md
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.