CVE-2025-63296

MEDIUM

KERUI K259 Firmware v33.53.87 - Unauthenticated Remote Code Execution via Update Script Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-63296. PoCs published by t4e-3.

AI-analyzed exploit summary CVE-2025-63296 exploits a code execution vulnerability in KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87. The vulnerability allows an attacker with physical access to execute arbitrary commands as root by placing a malicious script named 'update.nor.sh' on an SD/TF card, which is then copied and executed by the device during startup.

Description

KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot/update logic: during startup /usr/sbin/anyka_service.sh scans mounted TF/SD cards and, if /mnt/update.nor.sh is present, copies it to /tmp/net.sh and executes it as root.

Exploits (1)

nomisec WORKING POC
by t4e-3 · poc
https://github.com/t4e-3/CVE-2025-63296

CVE-2025-63296 exploits a code execution vulnerability in KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87. The vulnerability allows an attacker with physical access to execute arbitrary commands as root by placing a malicious script named 'update.nor.sh' on an SD/TF card, which is then copied and executed by the device during startup.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87
No auth needed
Prerequisites: Physical access to the device · SD/TF card
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory
https://github.com/t4e-3/CVE-2025-63296

Scores

CVSS v3 6.5
EPSS 0.0028
EPSS Percentile 19.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
keruistore/kerui_k259_firmware 33.53.87
Published Nov 10, 2025
Tracked Since Feb 18, 2026