Junglewise Threat Intelligence

CVE-2025-67158: Revotech I6032W-FHW authentication bypass in jvsweb.cgi

CVE-2025-67158 · Severity: high · CVSS 7.5 · Published 2026-01-02

Executive brief

Revotech I6032W-FHW IP cameras, which are used for video surveillance, contain a security flaw that allows unauthorized individuals to bypass login requirements. By sending a specially crafted web request, an attacker can access the camera's administrative interface without a password. This could lead to the exposure of sensitive user information, unauthorized access to video feeds, and full control over the device's settings.

Technical details

An authentication bypass vulnerability exists in the /cgi-bin/jvsweb.cgi endpoint of Revotech I6032W-FHW IP cameras running firmware version 1.0.0014 (20210517). The root cause is a failure to validate the 'user.name' and 'user.digest' fields within JSON-formatted API requests. An unauthenticated attacker can send crafted HTTP requests with arbitrary values in these fields to invoke administrative methods, such as 'account_get_users'. This allows for remote information disclosure and privilege escalation without any user interaction. Users are advised to restrict network access to the management interface and apply firmware updates if available.

Affected products

  • Revotech I6032W-FHW firmware 1.0.0014 - 20210517

Timeline

  • 2026-01-02: disclosed: Initial NVD publication date
  • 2026-01-02: advisory: Public disclosure of CVE-2025-67158

References