CVE-2025-12636 Details
Description
The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to backend services. The attacker would then be able to gain unauthorized access to available cameras, enabling the viewing of live feeds or modification of settings.
A vulnerability exists in the Ubia camera ecosystem, specifically in the Ubox product version 1.1.124, due to inadequate protection of API credentials. This flaw could allow an attacker to connect to backend services and gain unauthorized access to cameras, potentially enabling the viewing of live feeds or modification of camera settings.
Ubia has not responded to CISA's attempts to coordinate. Users are encouraged to contact Ubia support for more information. CISA recommends minimizing network exposure for control system devices, using firewalls to isolate these devices from business networks, and employing secure remote access methods such as VPNs. Organizations should also follow CISA's recommended practices for ICS cybersecurity and report any suspected malicious activity to CISA.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 6, 2025CISA-ADP
Assessed Nov 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Ubia Ubox | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 6, 2025 | New CVE Received | [email protected] |
Volerion