CVE-2025-10264 Details
Description
Certain models of NVR developed by Digiever has an Exposure of Sensitive Information vulnerability, allowing unauthenticated remoter attackers to access the system configuration file and obtain plaintext credentials of the NVR and its connected cameras.
A vulnerability allowing unauthenticated remote attackers to access the system configuration file of certain Digiever NVR models. This access enables the retrieval of plaintext credentials for the NVR and its connected cameras. The vulnerability affects several NVR series models, including the DS-1200, DS-2100 Pro, DS-2100 Pro+, DS-2100 UHD, DS-2200 UHD, DS-2200 UHD+, DS-4200 Pro, DS-4200 Pro+, DS-4200 UHD, DS-4200 UHD+, DS-4100-RM, DS-4200-RM Pro+, DS-4200-RM UHD, DS-8x00-RM Pro+, DS-8x00-SRM Pro+, DS-8x00-RM UHD, DS-16x00-RM Pro+, and DS-16x00-RM UHD. The vulnerable firmware version is through x.x.x.78.
Users are advised to update the firmware to version x.x.x.79 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 12, 2025CISA-ADP
Assessed Sep 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.twcert.org.tw/en/cp-139-10376-a057c-2.html | [email protected] | AdvisoryBundleRemedy |
| https://www.twcert.org.tw/tw/cp-132-10375-19f1e-1.html | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-497 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Digiever DS-1200 | All versions |
CPE
Remediation
| |
| Digiever DS-2100 Pro | All versions |
CPE
Remediation
| |
| Digiever DS-2100 Pro+ | All versions |
CPE
Remediation
| |
| Digiever DS-2100 UHD | All versions |
CPE
Remediation
| |
| Digiever DS-2200 UHD | All versions |
CPE
Remediation
| |
| Digiever DS-2200 UHD+ | All versions |
CPE
Remediation
| |
| Digiever DS-4200 Pro | All versions |
CPE
Remediation
| |
| Digiever DS-4200 Pro+ | All versions |
CPE
Remediation
| |
| Digiever DS-4200 UHD | All versions |
CPE
Remediation
| |
| Digiever DS-4200 UHD+ | All versions |
CPE
Remediation
| |
| Digiever DS-4100-RM | All versions |
CPE
Remediation
| |
| Digiever DS-4200-RM Pro+ | All versions |
CPE
Remediation
| |
| Digiever DS-4200-RM UHD | All versions |
CPE
Remediation
| |
| Digiever DS-8x00-RM Pro+ | All versions |
CPE
Remediation
| |
| Digiever DS-8x00-SRM Pro+ | All versions |
CPE
Remediation
| |
| Digiever DS-8x00-RM UHD | All versions |
CPE
Remediation
| |
| Digiever DS-16x00-RM Pro+ | All versions |
CPE
Remediation
| |
| Digiever DS-16x00-RM UHD | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 12, 2025 | New CVE Received | [email protected] |
Volerion