{"id":"CVE-2025-53702","title":"Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks","summary":"Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same local network might send a crafted request to /cgi-bin/action endpoint and render the device completely unresponsive. …","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-755"],"vendor":"vimicro","product":"vs-ipc1002_firmware","affected":["vs-ipc1002_firmware = 1.1.0.18"],"published":"2025-10-23","updated":"2026-10-08","sourceUpdated":"2026-10-08T11:10:00.250","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-53702","references":[{"url":"https://cert.pl/en/posts/2025/10/CVE-2025-53701","label":"cvd@cert.pl"}],"tags":["nvd"],"epss":0.0023,"epssPercentile":0.1264,"ingestedAt":"2026-10-08T11:31:27.559Z","slug":"CVE-2025-53702","body":"## Overview\n\nVilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same local network might send a crafted request to /cgi-bin/action endpoint and render the device completely unresponsive. A manual restart of the device is required. \nThe vendor did not respond in any way. Only version 1.1.0.18 was tested, other versions might be vulnerable as well.\n\n## Affected\n\n- `vs-ipc1002_firmware = 1.1.0.18`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}