Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images and videos related to alarm events through access to “/alarms/<ALARM_ID>/<MEDIA>”, where the “MEDIA” parameter can take the value of “snapshot” or “video.mp4”. These media files contain images recorded by security cameras in response to triggered alerts.
CVSS
No CVSS.
References
Configurations
No configuration.
History
24 Nov 2025, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-24 13:16
Updated : 2025-11-25 22:16
NVD link : CVE-2025-41016
Mitre link : CVE-2025-41016
CVE.ORG link : CVE-2025-41016
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
