PT-2025-25352 · Amazon · Amazon Cloud Cam
Published
2025-06-12
·
Updated
2025-10-14
·
CVE-2025-6031
CVSS v3.1
7.5
High
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Amazon Cloud Cam (affected versions not specified)
Description
The issue concerns a home security camera that is no longer supported due to its end-of-life status. When powered on, the device attempts to connect to a deprecated remote service infrastructure, defaulting to a pairing status. This allows an arbitrary user to bypass SSL pinning, associate the device with any network, and potentially intercept and modify network traffic.
Recommendations
Discontinue usage of any remaining Amazon Cloud Cams.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amazon Cloud Cam