CVE-2025-70962

HIGH

Zosi C519M 4.2.8.823C01450BA - Unauthenticated Information Disclosure via Hardcoded RTSP Credentials

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-70962. PoCs published by namaek2.

AI-analyzed exploit summary Technical analysis of CVE-2025-70962, a hard-coded credentials vulnerability in ZOSI C519M IP camera RTSP service (firmware V4.2.8.832C01450BA). The `admin:admin` credential is stored in plaintext in `/app/config.xml` and accepted by the RTSP service on TCP/554, allowing unauthenticated remote access to the live video feed.

Description

Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can use the unchangeable default credentials to access the RTSP video stream, resulting in unauthorized viewing of camera footage.

Exploits (1)

github WRITEUP
by namaek2 · poc
https://github.com/namaek2/CVE-2025-70962

Technical analysis of CVE-2025-70962, a hard-coded credentials vulnerability in ZOSI C519M IP camera RTSP service (firmware V4.2.8.832C01450BA). The `admin:admin` credential is stored in plaintext in `/app/config.xml` and accepted by the RTSP service on TCP/554, allowing unauthenticated remote access to the live video feed.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: ZOSI C519M IP camera (firmware V4.2.8.832C01450BA)
No auth needed
Prerequisites: Network reachability to the camera's RTSP service (TCP/554)
mistral-large-3 · analyzed Aug 05, 2026 Full analysis →

Scores

CVSS v3 7.5
EPSS 0.0038
EPSS Percentile 31.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-284
Status published
Published Aug 05, 2026
Tracked Since Aug 05, 2026