CVE-2025-1739

HIGH

Trivision Camera NC227WF v5.8.0 - Auth Bypass

Title source: llm

Description

An Authentication Bypass vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity. This vulnerability allows an attacker to retrieve administrator's credentials in cleartext by sending a request against the server using curl with random credentials to "/en/player/activex_pal.asp" and successfully authenticating the application.

Exploits (1)

nomisec WORKING POC
by n0n4m3x41 · poc
https://github.com/n0n4m3x41/CVE-2025-1739

Scores

CVSS v3 7.1
EPSS 0.0004
EPSS Percentile 12.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Details

CWE
CWE-288
Status published
Products (1)
Trivision/Camera NC227WF 5.8.0
Published Feb 27, 2025
Tracked Since Feb 18, 2026