Junglewise Threat Intelligence

CVE-2026-15683: Lorex 2K Indoor Wi-Fi Security Camera improper certificate validation

CVE-2026-15683 · Severity: high · CVSS 7.5 · Published 2026-07-13

Executive brief

A security vulnerability exists in Lorex 2K Indoor Wi-Fi Security Cameras that could allow an attacker on the same local network to take control of the device. By exploiting a failure in how the camera verifies secure connections, an attacker can potentially run unauthorized commands and gain full administrative access. This could lead to unauthorized access to video feeds, loss of privacy, or the camera being used as a foothold for further attacks on the home or business network.

Technical details

An improper certificate validation vulnerability (CWE-295) exists within the device management server functionality of Lorex 2K Indoor Wi-Fi Security Cameras. The root cause is the device's failure to verify the authenticity of certificates presented by the management server during communication. A network-adjacent attacker can exploit this flaw, potentially in conjunction with other vulnerabilities, to perform a man-in-the-middle attack and execute arbitrary code with root privileges. No user interaction is required for exploitation. As of the advisory date, the vendor indicated a fix was in progress, but no specific patched version was confirmed.

Affected products

  • Lorex 2K Indoor Wi-Fi Security Camera 2.800.020000000.3.R.20220331

Timeline

  • 2025-05-06: disclosed: Vulnerability reported to vendor by ZDI
  • 2026-07-08: advisory: Initial public release of advisory by ZDI
  • 2026-07-13: advisory: NVD publication date

References

Related threats