CVE-2025-41016
Last modified
CVE-2025-41016 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images and videos related to alarm events through access to “/alarms/<ALARM_ID>/<MEDIA>”, where the “MEDIA” parameter can take the value of “snapshot” or “video.mp4”. These media files contain images recorded by security cameras in response to triggered alerts.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images and videos related to alarm events through access to “/alarms/<ALARM_ID>/<MEDIA>”, where the “MEDIA” parameter can take the value of “snapshot” or “video.mp4”. These media files contain images recorded by security cameras in response to triggered alerts.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-41016?
How severe is CVE-2025-41016?
How do I fix CVE-2025-41016?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-41010Incorrect Cross-Origin Resource Sharing (CORS) configuration…5.1
- CVE-2025-41011HTML injection vulnerability in PHP Point of Sale v19.4. Thi…6.1
- CVE-2025-41012Unauthorized access vulnerability in TCMAN GIM v11 version 2…5.3
- CVE-2025-41013SQL injection vulnerability in TCMAN GIM v11 in version 2025…9.8
- CVE-2025-41014User Enumeration Vulnerability in TCMAN GIM v11 version 2025…7.5
- CVE-2025-41015User Enumeration Vulnerability in TCMAN GIM v11 version 2025…7.5
- CVE-2025-41017Inadequate access control vulnerability in Davantis DDFUSION…6.9
- CVE-2025-41018SQL injection in Sergestec's Exito v8.0. This vulnerability …9.8
- CVE-2025-41019SQL injection in Sergestec's SISTICK v7.2. This vulnerabilit…9.3
- CVE-2025-4102The Beaver Builder Plugin (Starter Version) plugin for WordP…7.2
- CVE-2025-41020Insecure direct object reference (IDOR) vulnerability in Ser…7.5
- CVE-2025-41021Stored Cross-Site Scripting (XSS) in Sergestec's Exito v8.0,…5.4
Are you affected by CVE-2025-41016?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
