CVE-2025-10264
CRITICAL
10.0
CVSS 3.1
Description
Certain models of NVR developed by Digiever has an Exposure of Sensitive Information vulnerability, allowing unauthenticated remoter attackers to access the system configuration file and obtain plaintext credentials of the NVR and its connected cameras.
Metadata
Severity & Metrics
10.0
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (18)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Digiever | DS-1200 | — | 0 ≤ *.*.*.78 |
| Digiever | DS-16x00-RM Pro+ | — | 0 ≤ x.x.x.78 |
| Digiever | DS-16x00-RM UHD | — | 0 ≤ x.x.x.78 |
| Digiever | DS-2100 Pro | — | 0 ≤ *.*.*.78 |
| Digiever | DS-2100 Pro+ | — | 0 ≤ *.*.*.78 |
| Digiever | DS-2100 UHD | — | 0 ≤ *.*.*.78 |
| Digiever | DS-2200 UHD | — | 0 ≤ *.*.*.78 |
| Digiever | DS-2200 UHD+ | — | 0 ≤ *.*.*.78 |
| Digiever | DS-4100-RM | — | 0 ≤ x.x.x.78 |
| Digiever | DS-4200 Pro | — | 0 ≤ *.*.*.78 |
| Digiever | DS-4200 Pro+ | — | 0 ≤ x.x.x.78 |
| Digiever | DS-4200 UHD | — | 0 ≤ x.x.x.78 |
| Digiever | DS-4200 UHD+ | — | 0 ≤ x.x.x.78 |
| Digiever | DS-4200-RM Pro+ | — | 0 ≤ x.x.x.78 |
| Digiever | DS-4200-RM UHD | — | 0 ≤ x.x.x.78 |
| Digiever | DS-8x00-RM Pro+ | — | 0 ≤ x.x.x.78 |
| Digiever | DS-8x00-RM UHD | — | 0 ≤ x.x.x.78 |
| Digiever | DS-8x00-SRM Pro+ | — | 0 ≤ x.x.x.78 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-497 | cna | CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 10.0 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| 10.0 | CRITICAL | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
References (2)