CVE-2025-9380 – FNKvision Y215 CCTV Camera Firmware Hard-coded Credentials Vulnerability

The following table lists the changes that have been made to the
CVE-2025-9380 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 24, 2025

    Action Type Old Value New Value
    Added Description A vulnerability was identified in FNKvision Y215 CCTV Camera 10.194.120.40. Affected by this issue is some unknown functionality of the file /etc/passwd of the component Firmware. Such manipulation leads to hard-coded credentials. Local access is required to approach this attack. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
    Added CVSS V4.0 AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Added CVSS V2 (AV:L/AC:L/Au:S/C:C/I:C/A:C)
    Added CWE CWE-798
    Added CWE CWE-259
    Added Reference https://vorachat.somsuay.com/blog/Hacking%20CCTV%20FNKvision%20-%20Y215
    Added Reference https://vorachat.somsuay.com/blog/Hacking%20CCTV%20FNKvision%20-%20Y215/#vulnerability-1-hardcoded-root-credentials-in-multiple-binaries
    Added Reference https://vuldb.com/?ctiid.321213
    Added Reference https://vuldb.com/?id.321213
    Added Reference https://vuldb.com/?submit.629810
Share the Post:

Related Posts