CVE-2025-25680 is a Remote Code Execution (RCE) vulnerability in LSC Smart Connect LSC Indoor PTZ Camera firmware version 7.6.32 and earlier, specifically within the tuya_ipc_direct_connect function of the anyka_ipc process. An attacker can exploit this by presenting a specially crafted QR code to the camera during the Wi-Fi configuration process, leading to arbitrary code execution. With a CVSS score of 7.7 (High), this vulnerability has a network attack vector and high impact on confidentiality and integrity, though it requires high attack complexity. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.6.32CPE matchmatch criteria | cpe:2.3:o:lsc:ptz_dual_band_camera_firmware:7.6.32:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.