CVE-2025-55810 Details
Description
A vulnerability was found in Alaga Home Security WiFi Camera 3K (model S-CW2503C-H) with hardware version V03 and firmware version 1.4.2, which allows physical attackers to execute commands as root via script file with a specific name on a SD card.
A privilege escalation vulnerability has been identified in the Alaga Home Security WiFi Camera 3K, model S-CW2503C-H, with hardware version V03 and firmware version 1.4.2. This vulnerability allows physical attackers to execute commands as root by placing a script file with a specific name onto an SD card. The camera's boot sequence includes a script that searches for these files and executes them with root privileges, potentially leading to unauthorized access or control over the device.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.alagaai.com/ | [email protected] | Product |
| https://www.mgm-sp.com/privilege-escalation-vulnerability-in-alaga-home-security-wifi-camera | [email protected] | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| alagaai s-cw2503c-h firmware | 1.4.2 |
CPE
Remediation
| |
| alagaai s-cw2503c-h | 03 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 9, 2026 | Initial Analysis | [email protected] |
| Nov 14, 2025 | CVE Modified | CISA-ADP |
| Nov 14, 2025 | CVE Modified | CISA-ADP |
| Nov 13, 2025 | New CVE Received | [email protected] |