Vulnerability Description
Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attackers to access sensitive API endpoints without authentication.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Simicam | Ip Camera Firmware | 1.16.41 |
| Simicam | Ip Camera | - |
| Keview | Ip Camera Firmware | 1.14.92 |
| Keview | Ip Camera | - |
| Asecam | Ip Camera Firmware | 1.14.10 |
| Asecam | Ip Camera | - |
Related Weaknesses (CWE)
References
- https://github.com/Remenis/CVE-2025-63667MitigationThird Party Advisory
- https://github.com/Remenis/Vatilon_evidence/releases/download/Evidence/Vatilon_vBroken Link
- https://vatilon.com/
FAQ
What is CVE-2025-63667?
CVE-2025-63667 is a vulnerability with a CVSS score of 7.5 (HIGH). Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attackers to access sensitive API endpoints without authentication.
How severe is CVE-2025-63667?
CVE-2025-63667 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-63667?
Check the references section above for vendor advisories and patch information. Affected products include: Simicam Ip Camera Firmware, Simicam Ip Camera, Keview Ip Camera Firmware, Keview Ip Camera, Asecam Ip Camera Firmware.