PT-2025-38711 · Galayou · Galayou G2 Cameras

Szymon Paszun

·

Published

2025-09-22

·

Updated

2025-09-22

·

CVE-2025-9983

CVSS v4.0

7.1

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GALAYOU G2 cameras version 11.100001.01.28
Description GALAYOU G2 cameras stream video output via RTSP streams. By default, these streams are protected by randomly generated credentials, but these credentials are not required to access the stream. Changing these credentials does not alter the camera's behavior.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9983

Affected Products

Galayou G2 Cameras