PT-2025-47904 · Davantis · Davantis Ddfusion

Ferran Plaza

·

Published

2025-11-24

·

Updated

2025-11-24

·

CVE-2025-41017

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Davantis DDFUSION version 6.177.7
Description An inadequate access control issue exists in the software that allows unauthorized actors to retrieve perspective parameters from security camera settings. This is achieved by accessing the ''/cameras//perspective'' API endpoint, where CAMERA ID represents the identifier of the security camera.
Recommendations Apply access controls to restrict access to the ''/cameras//perspective'' API endpoint.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-41017

Affected Products

Davantis Ddfusion