CVE-2025-6031 describes an insecure device pairing vulnerability in the end-of-life Amazon Cloud Cam. When powered on, the deprecated device attempts to connect to a non-existent service, defaulting to a pairing state where an attacker can bypass SSL pinning to associate it with an arbitrary network, enabling traffic interception and modification. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating a high potential for impact (confidentiality, integrity, availability) with an adjacent attack vector and high attack complexity. Users are strongly advised to discontinue using these devices. There is no evidence of active exploitation, nor are there known public exploit codes (Metasploit, Nuclei, ExploitDB). Community discussion and media coverage are minimal, suggesting low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Amazon | Cloud Cam | >= 0, <= *CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.