CVE-2025-25680

LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when a specially crafted QR code is presented to the camera.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:lsc:ptz_dual_band_camera_firmware:7.6.32:*:*:*:*:*:*:*
cpe:2.3:h:lsc:ptz_dual_band_camera:-:*:*:*:*:*:*:*

History

07 Jul 2025, 18:16

Type Values Removed Values Added
References () https://github.com/Yasha-ops/LSC_Indoor_PTZ_Camera-RCE - () https://github.com/Yasha-ops/LSC_Indoor_PTZ_Camera-RCE - Broken Link
References () https://github.com/Yasha-ops/vulnerability-research/tree/master/CVE-2025-25680 - () https://github.com/Yasha-ops/vulnerability-research/tree/master/CVE-2025-25680 - Exploit
First Time Lsc ptz Dual Band Camera
Lsc
Lsc ptz Dual Band Camera Firmware
CPE cpe:2.3:h:lsc:ptz_dual_band_camera:-:*:*:*:*:*:*:*
cpe:2.3:o:lsc:ptz_dual_band_camera_firmware:7.6.32:*:*:*:*:*:*:*

21 Mar 2025, 21:15

Type Values Removed Values Added
CWE CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.7
Summary
  • (es) LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 contiene una vulnerabilidad de RCE en la función tuya_ipc_direct_connect del proceso anyka_ipc. Esta vulnerabilidad permite la ejecución de código arbitrario durante la configuración de Wi-Fi al presentar un código QR especialmente manipulado a la cámara.

11 Mar 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 16:15

Updated : 2025-07-07 18:16


NVD link : CVE-2025-25680

Mitre link : CVE-2025-25680

CVE.ORG link : CVE-2025-25680


JSON object : View

Products Affected

lsc

  • ptz_dual_band_camera_firmware
  • ptz_dual_band_camera
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')