← Back to searchJSON

CVE-2025-70962

7.5 HIGHpublic exploit available

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows network attackers to access hardcoded credentials in RTSP authentication, enabling unauthorized viewing of camera footage.
Exploitability
Exploitation is relatively easy as it requires only network access and knowledge of default credentials.
Blast radius
If exploited, this could lead to widespread unauthorized surveillance of protected areas.
Prioritized remediation
Update the firmware to remove hardcoded credentials and enforce strong authentication mechanisms.
auth-bypassvideo-streamingnetwork-security

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can use the unchangeable default credentials to access the RTSP video stream, resulting in unauthorized viewing of camera footage.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-284

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.