CVE-2025-25680

LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when a specially crafted QR code is presented to the camera.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:lsc:ptz_dual_band_camera_firmware:7.6.32:*:*:*:*:*:*:*
cpe:2.3:h:lsc:ptz_dual_band_camera:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-03-11 16:15

Updated : 2025-07-07 18:16


NVD link : CVE-2025-25680

Mitre link : CVE-2025-25680

CVE.ORG link : CVE-2025-25680


JSON object : View

Products Affected

lsc

  • ptz_dual_band_camera_firmware
  • ptz_dual_band_camera
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')