CVE-2025-56438
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-10-24
Last updated on: 2025-10-27
Assigner: MITRE
Description
Description
An issue in the firmware update mechanism of Nous W3 Smart WiFi Camera v1.33.50.82 allows unauthenticated and physically proximate attackers to escalate privileges to root via supplying a crafted update.tar archive file stored on a FAT32-formatted SD card.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nous | w3_smart_wifi_camera | 1.33.50.82 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-345 | The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the firmware update mechanism of the Nous W3 Smart WiFi Camera version 1.33.50.82. It allows an attacker who is physically near the device and unauthenticated to escalate their privileges to root by supplying a specially crafted update.tar archive file on a FAT32-formatted SD card.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability can gain root-level access to the affected camera, potentially allowing them to fully control the device, access sensitive data, modify firmware, or disrupt device functionality.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70