CVE-2025-6532 Details
Description
A vulnerability classified as problematic was found in NOYAFA/Xiami LF9 Pro up to 20250611. Affected by this vulnerability is an unknown functionality of the component RTSP Live Video Stream Endpoint. The manipulation leads to improper access controls. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. This dashcam is distributed by multiple resellers and different names.
A vulnerability allowing improper access control has been identified in the NOYAFA Xiami LF9 Pro dashcam, in versions prior to 20250611. This vulnerability exists in the RTSP Live Video Stream Endpoint, where an attacker can access the live video feed and download all recorded videos without any authentication. The exploitation can be performed remotely, but only within the local network.
It is recommended to implement proper firewall rules to block unauthorized access to the dashcam's video stream and recorded files.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/geo-chen/LF9?tab=readme-ov-file#finding-1-unauthenticated-access-of-livestream-and-download-of-video-recordings | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/geo-chen/LF9 | [email protected] | ExploitThird Party Advisory |
| https://github.com/geo-chen/LF9?tab=readme-ov-file#finding-1-unauthenticated-access-of-livestream-and-download-of-video-recordings | [email protected] | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.313651 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.313651 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.595453 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| noyafa lf9 pro firmware | <= 2025-06-11 |
CPE
Remediation
| |
| noyafa lf9 pro | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Oct 1, 2025 | Initial Analysis | [email protected] |
| Jun 25, 2025 | CVE Modified | CISA-ADP |
| Jun 24, 2025 | New CVE Received | [email protected] |