CVE-2025-1739

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Feb 27, 2025
CWE ID 288

Summary

CVE-2025-1739 is an Authentication Bypass vulnerability affecting Trivision Camera NC227WF version 5.8.0 from TrivisionSecurity. By sending a crafted request to the server's "/en/player/activex_pal.asp" endpoint using curl, an attacker can bypass authentication and retrieve administrator credentials in cleartext. Successful exploitation of this vulnerability allows unauthorized access to the camera system with full administrative privileges. This issue poses a significant risk to the security of affected devices, requiring immediate patching or mitigation strategies.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share