CVE-2025-70962
Last modified
CVE-2025-70962 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism.
Description
Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can use the unchangeable default credentials to access the RTSP video stream, resulting in unauthorized viewing of camera footage.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2025-70962?
How severe is CVE-2025-70962?
How do I fix CVE-2025-70962?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-70956A State Pollution vulnerability was discovered in the TON Vi…7.5
- CVE-2025-70957A Denial of Service (DoS) vulnerability was discovered in th…7.5
- CVE-2025-70958Multiple reflected cross-site scripting (XSS) vulnerabilitie…6.1
- CVE-2025-70959A stored cross-site scripting (XSS) vulnerability in the Job…5.4
- CVE-2025-7096A vulnerability classified as critical was found in Comodo I…8.8
- CVE-2025-70960A stored cross-site scripting (XSS) vulnerability in the For…5.4
- CVE-2025-70963Gophish <=0.12.1 is vulnerable to Incorrect Access Control. …7.6
- CVE-2025-70968FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cp…9.8
- CVE-2025-7097A vulnerability, which was classified as critical, has been …8.8
- CVE-2025-70973ScadaBR 1.12.4 is vulnerable to Session Fixation. The applic…4.8
- CVE-2025-70974Fastjson before 1.2.48 mishandles autoType because, when an …10
- CVE-2025-7098A vulnerability, which was classified as critical, was found…8.8
Are you affected by CVE-2025-70962?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
