PT-2025-43970 · Honeywell · Honeywell S35 Series Cameras

Published

2025-10-27

·

Updated

2025-10-27

·

CVE-2025-12351

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Honeywell S35 Series Cameras versions prior to 2025.08.28 (Pinhole/Kit Camera) Honeywell S35 Series Cameras versions prior to 2025.08.22 (AI Fisheye & Dual Sensor/Micro Dome/Full Color Eyeball & Bullet Camera) Honeywell S35 Series Cameras versions prior to 2025.08.26 (Thermal Camera)
Description An authorization bypass exists in Honeywell S35 Series Cameras through the User controller key. Successful exploitation of this issue could allow an attacker to achieve privilege escalation to admin-level functionalities.
Recommendations Update S35 Pinhole/Kit Camera to version 2025.08.28. Update S35 AI Fisheye & Dual Sensor/Micro Dome/Full Color Eyeball & Bullet Camera to version 2025.08.22. Update S35 Thermal Camera to version 2025.08.26.

Fix

IDOR

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2025-12351

Affected Products

Honeywell S35 Series Cameras