CVE-2025-6522

MEDIUM

Sight Bulb Pro Firmware ZJ_CG32-2201 <8.57.83 - Unauthenticated OS Command Injection via TCP Port 16668

Title source: llm
STIX 2.1

Description

Unauthenticated users on an adjacent network with the Sight Bulb Pro can run shell commands as root through a vulnerable proprietary TCP protocol available on Port 16668. This vulnerability allows an attacker to run arbitrary commands on the Sight Bulb Pro by passing a well formed JSON string.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-25-177-02

Scores

CVSS v3 5.4
EPSS 0.0020
EPSS Percentile 9.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-77
Status published
Products (1)
TrendMakers/Sight Bulb Pro Firmware ZJ_CG32-2201 < 8.57.83
Published Jun 27, 2025
Tracked Since Feb 18, 2026