PT-2025-47326 · Unknown · Local Agent Dvr

Eric M. Holub

·

Published

2025-11-18

·

Updated

2025-12-31

·

CVE-2025-63408

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Local Agent DVR versions through 6.6.1.0
Description Local Agent DVR is affected by a directory traversal issue. An unauthenticated local attacker can exploit this to access sensitive information, conduct a server-side forgery request (SSRF), or execute operating system commands. The issue allows an attacker to traverse directories and potentially access files or execute code on the system.
Recommendations Update Local Agent DVR to a version later than 6.6.1.0.

Exploit

Fix

RCE

Path traversal

SSRF

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-63408

Affected Products

Local Agent Dvr