PT-2025-43970 · Honeywell · Honeywell S35 Series Cameras
Published
2025-10-27
·
Updated
2025-10-27
·
CVE-2025-12351
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Honeywell S35 Series Cameras versions prior to 2025.08.28 (Pinhole/Kit Camera)
Honeywell S35 Series Cameras versions prior to 2025.08.22 (AI Fisheye & Dual Sensor/Micro Dome/Full Color Eyeball & Bullet Camera)
Honeywell S35 Series Cameras versions prior to 2025.08.26 (Thermal Camera)
Description
An authorization bypass exists in Honeywell S35 Series Cameras through the
User controller key. Successful exploitation of this issue could allow an attacker to achieve privilege escalation to admin-level functionalities.Recommendations
Update S35 Pinhole/Kit Camera to version 2025.08.28.
Update S35 AI Fisheye & Dual Sensor/Micro Dome/Full Color Eyeball & Bullet Camera to version 2025.08.22.
Update S35 Thermal Camera to version 2025.08.26.
Fix
IDOR
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Honeywell S35 Series Cameras