CVE-2025-5124 is a critical vulnerability affecting the administrative interface of several Sony SNC series IP cameras (SNC-M1, SNC-M3, SNC-RZ25N, SNC-RZ30N, SNC-DS10, SNC-CS3N, and SNC-RX570N up to version 1.30), allowing for the use of default credentials. With a CVSS score of 8.1 (HIGH), this vulnerability can be exploited remotely with high attack complexity, potentially leading to full compromise of confidentiality, integrity, and availability. While the exploit has been publicly disclosed, its real existence is currently doubted, and exploitation is considered difficult. Despite public disclosure, there is no evidence of active exploitation, no known exploit tools like Metasploit or Nuclei, and minimal community discussion or media coverage. Sony has acknowledged the issue and recommends users change initial passwords, referencing their "Hardening Guide."
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Sony | SNC-CS3N | 1.0, 1.1, 1.10, 1.11, 1.12, 1.13, 1.14, 1.15, 1.16, 1.17, 1.18, 1.19, 1.2, 1.20, 1.21, 1.22, 1.23, 1.24, 1.25, 1.26, 1.27, 1.28, 1.29, 1.3, 1.30, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9CNA affected | |
| Sony | SNC-DS10 | 1.0, 1.1, 1.10, 1.11, 1.12, 1.13, 1.14, 1.15, 1.16, 1.17, 1.18, 1.19, 1.2, 1.20, 1.21, 1.22, 1.23, 1.24, 1.25, 1.26, 1.27, 1.28, 1.29, 1.3, 1.30, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9CNA affected | |
| Sony | SNC-M1 | 1.0, 1.1, 1.10, 1.11, 1.12, 1.13, 1.14, 1.15, 1.16, 1.17, 1.18, 1.19, 1.2, 1.20, 1.21, 1.22, 1.23, 1.24, 1.25, 1.26, 1.27, 1.28, 1.29, 1.3, 1.30, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9CNA affected | |
| Sony | SNC-M3 | 1.0, 1.1, 1.10, 1.11, 1.12, 1.13, 1.14, 1.15, 1.16, 1.17, 1.18, 1.19, 1.2, 1.20, 1.21, 1.22, 1.23, 1.24, 1.25, 1.26, 1.27, 1.28, 1.29, 1.3, 1.30, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9CNA affected | |
| Sony | SNC-RX570N | 1.0, 1.1, 1.10, 1.11, 1.12, 1.13, 1.14, 1.15, 1.16, 1.17, 1.18, 1.19, 1.2, 1.20, 1.21, 1.22, 1.23, 1.24, 1.25, 1.26, 1.27, 1.28, 1.29, 1.3, 1.30, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.