CVE-2025-63674

An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootloader on the SD card.
References
Link Resource
http://a31c.com Broken Link
http://blurams.com Product
https://vindivlabs.com/research/lumi_part_2/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:blurams:a31c_firmware:23.1227.472.2926:*:*:*:*:*:*:*
cpe:2.3:h:blurams:a31c:-:*:*:*:*:*:*:*

History

30 Dec 2025, 17:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.1
v2 : unknown
v3 : 6.8
CPE cpe:2.3:h:blurams:a31c:-:*:*:*:*:*:*:*
cpe:2.3:o:blurams:a31c_firmware:23.1227.472.2926:*:*:*:*:*:*:*
First Time Blurams a31c Firmware
Blurams a31c
Blurams
References () http://a31c.com - () http://a31c.com - Broken Link
References () http://blurams.com - () http://blurams.com - Product
References () https://vindivlabs.com/research/lumi_part_2/ - () https://vindivlabs.com/research/lumi_part_2/ - Exploit, Third Party Advisory

24 Nov 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-24 22:15

Updated : 2025-12-30 17:24


NVD link : CVE-2025-63674

Mitre link : CVE-2025-63674

CVE.ORG link : CVE-2025-63674


JSON object : View

Products Affected

blurams

  • a31c
  • a31c_firmware
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')