CVE-2025-8761

7.5

INSTAR · 2K+ and 4K cameras

A denial of service vulnerability exists in the Backend IPC Server of INSTAR 2K+ and 4K cameras (version 3.11.1 Build 1124) that can be triggered by an unauthenticated remote attacker.

Executive summary

An unauthenticated remote attacker can cause a denial of service on INSTAR 2K+ and 4K cameras, rendering the devices unresponsive.

Vulnerability

This vulnerability involves a flaw in the Backend IPC Server component, which allows an unauthenticated remote attacker to send specifically crafted requests to trigger a denial of service condition. The issue arises from improper handling of incoming data, leading to system instability or service failure.

Business impact

A successful exploitation of this vulnerability results in the total loss of camera functionality, which is critical for physical security and surveillance operations. Given the CVSS score of 7.5, this high-severity flaw poses a significant operational risk, as attackers can remotely disable security monitoring systems without needing valid credentials.

Remediation

Immediate Action: Update the affected INSTAR 2K+ and 4K camera firmware to the latest version provided by the vendor, which addresses the IPC Server vulnerability.

Proactive Monitoring: Monitor network traffic for unusual spikes or malformed packets directed at the camera IPC interface and review system logs for unexpected service restarts.

Compensating Controls: Deploy a Web Application Firewall or network-level access control lists to restrict traffic to the camera management interface to trusted IP addresses only, thereby reducing the attack surface.

Exploitation status

Public Exploit Available: Yes — the vulnerability details and exploitation mechanism are documented in the modzero.com research publication.

Analyst recommendation

The high CVSS score and the existence of public technical documentation regarding the exploitation of the Backend IPC Server necessitate immediate attention. Organizations utilizing these cameras should prioritize firmware updates or implement strict network segmentation to prevent unauthorized remote access to these devices until patches can be verified and applied.

Sources

Originally found and disclosed by Michael Imfeld (modzero AG), per the CVE Program record.