CVE-2025-63674

MEDIUM

Blurams Lumi Security Camera <v23.1227.472.2926 - RCE

Title source: llm
STIX 2.1

Description

An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootloader on the SD card.

References (3)

Core 3
Core References
Broken Link
http://a31c.com
Exploit, Third Party Advisory
https://vindivlabs.com/research/lumi_part_2/

Scores

CVSS v3 6.8
EPSS 0.0029
EPSS Percentile 20.4%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
blurams/a31c_firmware 23.1227.472.2926
Published Nov 24, 2025
Tracked Since Feb 18, 2026