CVE-2019-25248 describes an unauthenticated vulnerability in Beward N100 M2.1.6.04C014 IP cameras, allowing remote attackers to access live video streams without requiring credentials. This high-severity flaw (CVSS 7.5) stems from a missing authentication mechanism (CWE-306) for the camera's RTSP stream, enabling direct retrieval of sensitive video feeds. While no active exploitation, public exploit code, or significant community discussion has been observed, the vulnerability presents a critical privacy risk due to unauthorized access to video surveillance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Beward | N100 H.264 VGA IP Camera | M2.1.6.04C014CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.