PT-2025-22840 · Sony · Sony Snc-Rz25N+6
Zeke
·
Published
2025-05-24
·
Updated
2025-06-07
·
CVE-2025-5124
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Sony SNC-M1, SNC-M3, SNC-RZ25N, SNC-RZ30N, SNC-DS10, SNC-CS3N and SNC-RX570N versions up to 1.30
Description
A critical vulnerability has been found in the Administrative Interface of the affected Sony cameras, allowing for the use of default credentials. This issue can be exploited remotely, but the complexity of the attack is considered high and the exploitability is difficult. The vendor has confirmed the existence of the vulnerability and recommends changing the initial passwords. A 'Hardening Guide' has been published to inform customers of the recommendation to change their initial passwords.
Recommendations
For Sony SNC-M1, SNC-M3, SNC-RZ25N, SNC-RZ30N, SNC-DS10, SNC-CS3N and SNC-RX570N versions up to 1.30, it is recommended to change the configuration settings, specifically the initial passwords, to prevent the use of default credentials.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sony Snc-Cs3N
Sony Snc-Ds10
Sony Snc-M1
Sony Snc-M3
Sony Snc-Rx570N
Sony Snc-Rz25N
Sony Snc-Rz30N