Home
HIGH: 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
affected
Any version
affected
Default status
affected
Any version
affected
Default status
affected
Any version
affected
Default status
affected
Any version
affected
Default status
affected
Any version
affected
Default status
affected
Any version
affected
Default status
affected
Any version
affected
Default status
affected
Any version
affected
Default status
affected
Any version
affected
Description
The Diviotec professional series exposes a web interface. One endpoint is vulnerable to arbitrary command injection and hardcoded passwords are used.
Problem types
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
Any version
Any version
Any version
Any version
Any version
Any version
Any version
Any version
Any version
Timeline
| 2025-03-04: | Notification email sent to sales@diviotec.com |
| 2025-04-15: | Notification email sent to sales@diviotec.com, support@diviotec.com, security@diviotec.com, psirt@diviotec.com, csirt@diviotec.com |
| 2025-04-27: | Notification email sent to sales@diviotec.com, support@diviotec.com, security@diviotec.com, psirt@diviotec.com, csirt@diviotec.com, and Nexcom personal emails |
Credits
ONEKEY Research Labs
References
www.onekey.com/...cution-on-diviotec-ip-camera-cve-2025-5113
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.