CVE-2025-52599

MEDIUM WAF: Low
CVSS 6.5 Published: 2025-12-26
CWE-269

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered Inadequate of permission management for camera guest account. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

WAF Coverage Analysis

Improper Privilege Management Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
hanwhavisionxnv-l6080r_firmwareup to 2.23.01
hanwhavisionxnd-l6080rva_firmwareup to 2.23.01
hanwhavisionxnd-l6080va_firmwareup to 2.23.01
hanwhavisionxno-l6080ra_firmwareup to 2.23.01
hanwhavisionxnv-l6080a_firmwareup to 2.23.01
hanwhavisionxnv-l6080ra_firmwareup to 2.23.01
hanwhavisionqnp-6320h_firmwareup to 2.23.01
hanwhavisionqnp-6320_firmwareup to 2.23.01
hanwhavisionqnp-6250h_firmwareup to 2.23.01
hanwhavisionqnp-6250_firmwareup to 2.23.01

References

Back to CVE Database