CVE-2025-25983 Details
Description
An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an attacker to obtain sensitive information via the QE code based sharing component.
A vulnerability in the V380 Pro Android application by Macro-video Technologies, affecting versions 2.1.44 and 2.1.64, allows attackers to extract sensitive information through the QR code sharing feature. The QR code includes a plaintext device ID, a key, and an encrypted message. The key can be used to decrypt the message, revealing plaintext login credentials. This issue arises because the application shares the decryption key alongside the encrypted data, undermining any security the encryption might provide.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/vladko312/Research_v380_IP_camera | [email protected] | ExploitProductThird Party Advisory |
| https://github.com/vladko312/Research_v380_IP_camera/blob/main/CVE-2025-25983.md | [email protected] | Exploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-257 | Storing Passwords in a Recoverable Format | CISA-ADP |
| CWE-656 | Reliance on Security Through Obscurity | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| macro-video v380 pro | 2.1.44 2.1.64 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2025 | Initial Analysis | [email protected] |
| Apr 18, 2025 | CVE Modified | CISA-ADP |
| Apr 18, 2025 | New CVE Received | [email protected] |