9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` parameter in the `/uapi-cgi/viewer/Param.cgi` script. This has been confirmed on the EFD-2130 camera running firmware version 1.12.0.19.
AI Analysis
Unauthenticated SQL Injection vulnerability in Geutebruck G-Cam Series Cameras
Basic Information
ID
CVE-2025-12463
Source
BLSOPS
Published
Nov 3, 2025 at 16:45
Modified
Nov 3, 2025 at 20:51
Affected Product
Vendor
Guetebruck
Product
G-Cam
Version
1.12.0.19
Affected Versions
Guetebruck G-Cam 1.12.0.19
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
Geutebruck
Product
G-Cam
Version
1.12.0.19