CVE-2025-25680

LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when a specially crafted QR code is presented to the camera.
Configurations

No configuration.

History

21 Mar 2025, 21:15

Type Values Removed Values Added
CWE CWE-94
Summary
  • (es) LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 contiene una vulnerabilidad de RCE en la función tuya_ipc_direct_connect del proceso anyka_ipc. Esta vulnerabilidad permite la ejecución de código arbitrario durante la configuración de Wi-Fi al presentar un código QR especialmente manipulado a la cámara.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.7

11 Mar 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 16:15

Updated : 2025-03-21 21:15


NVD link : CVE-2025-25680

Mitre link : CVE-2025-25680

CVE.ORG link : CVE-2025-25680


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')