CVE-2025-9983

HIGH

GALAYOU G2 - Unauthenticated RTSP Stream Access

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-9983. PoCs published by sohaibeb.

AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2025-9983, an RTSP credential bypass vulnerability in GALAYOU G2 security cameras. The exploit scans for accessible RTSP streams and verifies authentication bypass by testing streams without credentials, capturing video evidence from vulnerable streams.

Description

GALAYOU G2 cameras stream video output via RTSP streams. By default these streams are protected by randomly generated credentials. However these credentials are not required to access the stream. Changing these values does not change camera's behavior. The vendor did not respond in any way. Only version 11.100001.01.28 was tested, other versions might also be vulnerable.

Exploits (1)

github WORKING POC
by sohaibeb · pythonpoc
https://github.com/sohaibeb/CVE-2025-9983

This repository contains a functional Python exploit for CVE-2025-9983, an RTSP credential bypass vulnerability in GALAYOU G2 security cameras. The exploit scans for accessible RTSP streams and verifies authentication bypass by testing streams without credentials, capturing video evidence from vulnerable streams.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: GALAYOU G2 security cameras
No auth needed
Prerequisites: Python 3.x · FFmpeg tools (ffprobe and ffmpeg) · Network access to target device
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (2)

Core 2
Core References
Various Sources third-party-advisory
https://cert.pl/en/posts/2025/09/CVE-2025-9983
Various Sources product
https://www.galayou-store.com/g2

Scores

CVSS v4 7.1
EPSS 0.0064
EPSS Percentile 45.7%
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-306
Status published
Products (1)
GALAYOU/G2 11.100001.01.28
Published Sep 22, 2025
Tracked Since Feb 18, 2026