CVE-2025-70962
HIGHZosi C519M 4.2.8.823C01450BA - Unauthenticated Information Disclosure via Hardcoded RTSP Credentials
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-70962. PoCs published by namaek2.
AI-analyzed exploit summary Technical analysis of CVE-2025-70962, a hard-coded credentials vulnerability in ZOSI C519M IP camera RTSP service (firmware V4.2.8.832C01450BA). The `admin:admin` credential is stored in plaintext in `/app/config.xml` and accepted by the RTSP service on TCP/554, allowing unauthenticated remote access to the live video feed.
Description
Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can use the unchangeable default credentials to access the RTSP video stream, resulting in unauthorized viewing of camera footage.
Exploits (1)
Technical analysis of CVE-2025-70962, a hard-coded credentials vulnerability in ZOSI C519M IP camera RTSP service (firmware V4.2.8.832C01450BA). The `admin:admin` credential is stored in plaintext in `/app/config.xml` and accepted by the RTSP service on TCP/554, allowing unauthenticated remote access to the live video feed.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N