Junglewise Threat Intelligence

CVE-2025-67159: Vatilon IP Camera Firmware plaintext credential exposure in web.cgi

CVE-2025-67159 · Severity: high · CVSS 7.5 · Published 2026-01-02

Executive brief

Vatilon firmware used in IP cameras (such as JIENUO brand devices) contains a security flaw that transmits administrative usernames and passwords in plain text. This allows an unauthorized person on the network to intercept login credentials or bypass security checks to access the camera's web interface. An attacker could use this access to view live video feeds, change device settings, or gain full control over the camera.

Technical details

A vulnerability in the /cgi-bin/web.cgi API endpoint of Vatilon-based IP camera firmware (specifically version 1.12.37-20240124) stems from improper authentication and incorrect access control. The web interface processes HTTP GET requests containing 'username' and 'password' parameters in plaintext without enforcing server-side session validation. An unauthenticated remote attacker can exploit this by sending crafted API requests or accessing specific pages like /view/player.html to trigger unauthenticated API calls. This leads to the exposure of administrative credentials and sensitive device configuration data, potentially allowing for full device compromise.

Affected products

  • Vatilon PA4 Firmware 1.12.37-20240124

Timeline

  • 2025-01-02: disclosed: Initial CVE publication date
  • 2026-01-02: advisory: NVD publication date

References

Related threats