CVE-2025-63667

7.5

Vatilon · SIMICAM, KEVIEW, ASECAM

Multiple Vatilon products, including SIMICAM, KEVIEW, and ASECAM, contain an incorrect access control vulnerability that allows unauthenticated attackers to access sensitive API endpoints.

Executive summary

A critical access control vulnerability in Vatilon SIMICAM, KEVIEW, and ASECAM products allows unauthenticated attackers to gain unauthorized access to sensitive API data.

Vulnerability

This is an improper access control vulnerability where the affected software fails to enforce authentication checks, allowing unauthenticated remote attackers to interact with sensitive API functions.

Business impact

The vulnerability poses a high risk to organizational data confidentiality, as it permits unauthorized retrieval of sensitive information via exposed API endpoints. With a CVSS score of 7.5, this flaw represents a significant security gap, potentially leading to unauthorized data exposure and non-compliance with data protection mandates.

Remediation

Immediate Action: Contact Vatilon support or monitor the official vendor website for firmware or software patches, as no official fix is currently confirmed in the provided data.

Proactive Monitoring: Audit API access logs for unusual patterns, specifically monitoring for requests originating from unauthorized or unexpected IP addresses targeting sensitive endpoints.

Compensating Controls: Deploy a Web Application Firewall (WAF) to inspect and block unauthorized API requests and implement network-level access controls to restrict traffic to vulnerable devices.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept repository is available on GitHub via the referenced security research.

Analyst recommendation

Given the exposure of sensitive API endpoints to unauthenticated users, this vulnerability carries significant risk. Organizations utilizing affected Vatilon products must prioritize network isolation and enhanced monitoring until official vendor patches are deployed to fully remediate the underlying access control failure.

Sources