Executive brief
A vulnerability exists in Lorex 2K Indoor Wi-Fi Security Cameras, which are devices used for home and business surveillance. An attacker on the same local network can exploit this flaw to take complete control of the camera without needing a password. This could allow an unauthorized person to view private video feeds, disable the camera, or use the device as a foothold to attack other systems on the network.
Technical details
A format string vulnerability exists within the 'sonia' binary of the Lorex 2K Indoor Wi-Fi Security Camera. The flaw is located in the CDeviceOperator component during the parsing of JSON requests, where user-supplied strings are used as format specifiers without proper validation. An unauthenticated attacker positioned on the same local network (adjacent) can exploit this to execute arbitrary code with root privileges. As of the advisory date, no official patch has been confirmed, and the vendor indicated a fix was in progress; users are advised to restrict network access to the device.
Affected products
- Lorex 2K Indoor Wi-Fi Security Camera 2.800.020000000.3.R.20220331
Timeline
- 2025-07-08: disclosed: Vulnerability reported to vendor
- 2026-07-08: advisory: Coordinated public release of advisory
- 2026-07-13: other: Advisory updated and published to NVD