CVE-2025-5113 Details
Description
The Diviotec professional series exposes a web interface. One endpoint is vulnerable to arbitrary command injection and hardcoded passwords are used.
A vulnerability has been identified in the Diviotec professional series IP cameras, including models nbr222p, nbr222pv, nbr224p, nbr225p, nbr226p, nbf232p, nbf233p, ndr252p, and ndr255p. All versions of these cameras are affected. The vulnerability arises from arbitrary command injection in a CGI script called 'camctrl.cgi', which is executed by the 'apache' user. This script improperly sanitizes user input, allowing remote attackers to inject commands that are executed with elevated privileges. Additionally, the cameras use hardcoded passwords, which can be exploited to bypass authentication and access the vulnerable endpoint.
Affected cameras should be isolated from the Internet, default or weak passwords replaced, and a firmware update requested from Diviotec or Nexcomm. After applying the update, CGI scripts should be re-audited for proper input sanitization and unnecessary sudo privileges for the 'apache' user removed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 2, 2025CISA-ADP
Assessed Jun 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.onekey.com/resource/security-advisory-remote-code-execution-on-diviotec-ip-camera-cve-2025-5113 | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Diviotec nbr222p | <= 0 |
CPE
Remediation
| |
| Diviotec nbr222pv | <= 0 |
CPE
Remediation
| |
| Diviotec nbr224p | <= 0 |
CPE
Remediation
| |
| Diviotec nbr225p | <= 0 |
CPE
Remediation
| |
| Diviotec nbr226p | <= 0 |
CPE
Remediation
| |
| Diviotec nbf232p | <= 0 |
CPE
Remediation
| |
| Diviotec nbf233p | <= 0 |
CPE
Remediation
| |
| Diviotec ndr252p | <= 0 |
CPE
Remediation
| |
| Diviotec ndr255p | <= 0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2025 | New CVE Received | [email protected] |
Volerion