CVE-2025-25680

LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when a specially crafted QR code is presented to the camera.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:lsc:ptz_dual_band_camera_firmware:7.6.32:*:*:*:*:*:*:*
cpe:2.3:h:lsc:ptz_dual_band_camera:-:*:*:*:*:*:*:*

History

07 Jul 2025, 18:16

Type Values Removed Values Added
CPE cpe:2.3:o:lsc:ptz_dual_band_camera_firmware:7.6.32:*:*:*:*:*:*:*
cpe:2.3:h:lsc:ptz_dual_band_camera:-:*:*:*:*:*:*:*
First Time Lsc ptz Dual Band Camera Firmware
Lsc
Lsc ptz Dual Band Camera
References () https://github.com/Yasha-ops/LSC_Indoor_PTZ_Camera-RCE - () https://github.com/Yasha-ops/LSC_Indoor_PTZ_Camera-RCE - Broken Link
References () https://github.com/Yasha-ops/vulnerability-research/tree/master/CVE-2025-25680 - () https://github.com/Yasha-ops/vulnerability-research/tree/master/CVE-2025-25680 - Exploit

11 Mar 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 16:15

Updated : 2025-07-07 18:16


NVD link : CVE-2025-25680

Mitre link : CVE-2025-25680


JSON object : View

Products Affected

lsc

  • ptz_dual_band_camera
  • ptz_dual_band_camera_firmware
CWE

No CWE.