Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images and videos related to alarm events through access to “/alarms/<ALARM_ID>/<MEDIA>”, where the “MEDIA” parameter can take the value of “snapshot” or “video.mp4”. These media files contain images recorded by security cameras in response to triggered alerts.
Metrics
Affected Vendors & Products
References
History
Wed, 26 Nov 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Davantis
Davantis dfusion |
|
| Vendors & Products |
Davantis
Davantis dfusion |
Mon, 24 Nov 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Nov 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images and videos related to alarm events through access to “/alarms/<ALARM_ID>/<MEDIA>”, where the “MEDIA” parameter can take the value of “snapshot” or “video.mp4”. These media files contain images recorded by security cameras in response to triggered alerts. | |
| Title | Multiple vulnerabilities in DFUSION by Davantis | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-11-24T13:11:29.745Z
Reserved: 2025-04-16T09:09:25.290Z
Link: CVE-2025-41016
Updated: 2025-11-24T13:11:21.092Z
Status : Awaiting Analysis
Published: 2025-11-24T13:16:16.127
Modified: 2025-11-25T22:16:16.690
Link: CVE-2025-41016
No data.