CVE-2025-52598

⚪ Do wiadomości

Brak walidacji certyfikatów w usłudze klienckiej kamer umożliwia ataki typu man-in-the-middle.

CVSS
3.7
EPSS
0.2%
Exploit
none
Vendor
hanwhavision
Opis źródłowy (NVD)

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has found a flaw that camera's client service does not perform certificate validation. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS3.7
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2025-12-26 05:16:07 UTC
Ostatnia modyfikacja (NVD)2026-10-07 13:10:00 UTC
Referencje