Sricam Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Sricam products.
Products
- IP CCTV Camera2 vulnerabilities
- DeviceViewer1 vulnerability
- Sricam DeviceViewer1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2019-25436MEDIUM | Sricam DeviceViewer 3.12.0.1 Password Change Security BypassSricam DeviceViewer 3.12.0.1 contains a password change security bypass vulnerability that allows authenticated users to change passwords without proper validation of the old password field. Attackers can inject a large payload into the old password parameter during the change password process to bypass validation and set an arbitrary new password. CWE-303Feb 20, 2026 | CVSS5.1v4.0 | EPSS0.249% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25435HIGH | Sricam DeviceViewer 3.12.0.1 Local Buffer Overflow DEP BypassSricam DeviceViewer 3.12.0.1 contains a local buffer overflow vulnerability in the user management add user function that allows authenticated attackers to execute arbitrary code by bypassing data execution prevention. Attackers can inject a malicious payload through the Username field in User Management to trigger a stack-based buffer overflow and execute commands via ROP chain gadgets. CWE-121Feb 20, 2026 | CVSS8.4v4.0 | EPSS0.32% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25063MEDIUM | Sricam IP CCTV Camera Device Viewer memory corruptionA vulnerability was found in Sricam IP CCTV Camera. It has been classified as critical. Affected is an unknown function of the component Device Viewer. The manipulation leads to memory corruption. Local access is required to approach this attack. | CVSS5.3v3.1 | EPSS0.236% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25062MEDIUM | Sricam IP CCTV Camera Device Viewer stack-based overflowA vulnerability was found in Sricam IP CCTV Camera and classified as critical. This issue affects some unknown processing of the component Device Viewer. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. | CVSS5.3v3.1 | EPSS0.313% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |