---
id: CVE-2025-53702
title: Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks
summary: "Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same local network might send a crafted request to\_/cgi-bin/action endpoint and render the device completely unresponsive. …"
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-755
vendor: vimicro
product: vs-ipc1002_firmware
affected:
  - vs-ipc1002_firmware = 1.1.0.18
published: '2025-10-23'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-53702'
references:
  - url: 'https://cert.pl/en/posts/2025/10/CVE-2025-53701'
    label: cvd@cert.pl
tags:
  - nvd
epss: 0.0023
epssPercentile: 0.1264
ingestedAt: '2026-10-08T11:31:27.559Z'
---

## Overview

Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same local network might send a crafted request to /cgi-bin/action endpoint and render the device completely unresponsive. A manual restart of the device is required. 
The vendor did not respond in any way. Only version 1.1.0.18 was tested, other versions might be vulnerable as well.

## Affected

- `vs-ipc1002_firmware = 1.1.0.18`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
