CVE-2025-63667

HIGH

Simicam IP Camera Firmware - Improper Access Control

Title source: rule

Description

Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attackers to access sensitive API endpoints without authentication.

Exploits (1)

nomisec WRITEUP
by Remenis · poc
https://github.com/Remenis/CVE-2025-63667

Scores

CVSS v3 7.5
EPSS 0.0020
EPSS Percentile 42.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-284
Status published
Products (3)
asecam/ip_camera_firmware 1.14.10
keview/ip_camera_firmware 1.14.92
simicam/ip_camera_firmware 1.16.41
Published Nov 12, 2025
Tracked Since Feb 18, 2026