CVE-2025-65552 Details
Description
D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication channel. The system does not implement rolling codes, message authentication, or anti-replay protection, allowing an attacker within RF range to record valid alarm/control frames and replay them to trigger false alarms.
A vulnerability allowing RF replay attacks has been identified in the D3D Wi-Fi Home Security System ZX-G12, specifically in version 2.1.1. The issue arises from the 433 MHz sensor communication channel, which lacks essential security measures such as rolling codes, message authentication, and anti-replay protection. This absence allows an attacker within RF range to record valid alarm or control signals and replay them, potentially triggering false alarms.
Users are advised to avoid systems that rely on unencrypted RF communications for security. Vendors should implement rolling codes, add cryptographic message authentication, use nonces or timestamps, and adopt secure RF chipsets that comply with modern IoT security standards.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://d3dsecurity.com/products/wifi-home-security-system-model-g12 | CISA-ADP | Product |
| https://github.com/EmbdCDACHyd/CVE/tree/main/CVE-2025-65552 | CISA-ADP | Third Party Advisory |
| https://github.com/EmbdCDACHyd/CVE/tree/main/CVE-2025-65552 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-294 | Authentication Bypass by Capture-replay | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| d3dsecurity zx-g12 firmware | 2.1.17 |
CPE
Remediation
| |
| d3dsecurity zx-g12 | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 3, 2026 | Reanalysis | [email protected] |
| Jan 22, 2026 | Initial Analysis | [email protected] |
| Jan 13, 2026 | CVE Modified | CISA-ADP |
| Jan 12, 2026 | New CVE Received | [email protected] |