Vulnerability Description
LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when a specially crafted QR code is presented to the camera.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lsc | Ptz Dual Band Camera Firmware | 7.6.32 |
| Lsc | Ptz Dual Band Camera | - |
Related Weaknesses (CWE)
References
- https://github.com/Yasha-ops/LSC_Indoor_PTZ_Camera-RCEBroken Link
- https://github.com/Yasha-ops/vulnerability-research/tree/master/CVE-2025-25680Exploit
FAQ
What is CVE-2025-25680?
CVE-2025-25680 is a vulnerability with a CVSS score of 7.7 (HIGH). LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution throu...
How severe is CVE-2025-25680?
CVE-2025-25680 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-25680?
Check the references section above for vendor advisories and patch information. Affected products include: Lsc Ptz Dual Band Camera Firmware, Lsc Ptz Dual Band Camera.