CVE-2025-41016

Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images and videos related to alarm events through access to “/alarms/<ALARM_ID>/<MEDIA>”, where the “MEDIA” parameter can take the value of “snapshot” or “video.mp4”. These media files contain images recorded by security cameras in response to triggered alerts.
CVSS

No CVSS.

Configurations

No configuration.

History

24 Nov 2025, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-24 13:16

Updated : 2025-11-25 22:16


NVD link : CVE-2025-41016

Mitre link : CVE-2025-41016

CVE.ORG link : CVE-2025-41016


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization