We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
The Diviotec professional series exposes a web interface. One endpoint is vulnerable to arbitrary command injection and hardcoded passwords are used.
Reserved 2025-05-23 | Published 2025-06-02 | Updated 2025-06-02 | Assigner ONEKEYCWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
2025-03-04: | Notification email sent to sales@diviotec.com |
2025-04-15: | Notification email sent to sales@diviotec.com, support@diviotec.com, security@diviotec.com, psirt@diviotec.com, csirt@diviotec.com |
2025-04-27: | Notification email sent to sales@diviotec.com, support@diviotec.com, security@diviotec.com, psirt@diviotec.com, csirt@diviotec.com, and Nexcom personal emails |
ONEKEY Research Labs
www.onekey.com/...cution-on-diviotec-ip-camera-cve-2025-5113
Support options