6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Description
Inadequate access control vulnerability in Davantis DDFUSION v6.177.7, which allows unauthorised actors to retrieve perspective parameters from security camera settings by accessing “/cameras/<CAMERA_ID>/perspective”.
Basic Information
ID
CVE-2025-41017
Source
INCIBE
Published
Nov 24, 2025 at 12:20
Affected Product
Vendor
Davantis
Product
DFUSION
Version
prior to 6.186.1
Affected Versions
Davantis DFUSION prior to 6.186.1