CVE-2025-50777

7.8

AZIOT · 2MP Full HD Smart Wi-Fi CCTV Home Security Camera

The AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera contains an incorrect access control vulnerability allowing local attackers to obtain root shell access and plaintext credentials.

Executive summary

A critical incorrect access control vulnerability in the AZIOT 2MP Full HD Smart Wi-Fi CCTV camera allows local attackers to achieve root-level system compromise and intercept sensitive network credentials.

Vulnerability

The firmware suffers from an incorrect access control flaw that permits a local attacker with low privileges to escalate to a root shell. This access facilitates the extraction of sensitive information, specifically Wi-Fi and ONVIF service credentials, which are stored in plaintext.

Business impact

The exposure of root credentials and network access parameters presents a significant risk to organizational confidentiality and integrity. Successful exploitation could allow an adversary to pivot from the compromised camera into the internal network, leading to broader unauthorized access, potential data exfiltration, or the inclusion of the device in a malicious botnet. With a CVSS score of 7.8, the impact is considered High due to the potential for total system compromise.

Remediation

Immediate Action: Since a specific patch version is currently unknown, users should restrict physical access to the affected devices and isolate them from critical network segments using VLANs.

Proactive Monitoring: Monitor network traffic for unusual outbound connections originating from the CCTV devices, particularly towards unknown or external IP addresses.

Compensating Controls: Implement strict network segmentation to limit the blast radius of a compromised camera, ensuring it cannot communicate with sensitive internal assets or administrative interfaces.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the GitHub repository referenced in the CVE record.

Analyst recommendation

Given the severity of this access control failure and the availability of a public proof-of-concept, users must treat these devices as compromised if they are exposed to untrusted users. Organizations should prioritize isolating these cameras from production environments until the vendor provides a firmware update that addresses the root access flaw.

Sources