Threats Tagged 'cve-2025-41016'
View all threats tagged with 'cve-2025-41016'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-41016'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2025-41016 is a high-severity vulnerability in Davantis DFUSION versions prior to 6.186.1 that allows unauthenticated attackers to access sensitive media files such as snapshots and videos related to alarm events. The flaw stems from missing authorization checks on the endpoint /alarms/<ALARM_ID>/<MEDIA>, enabling unauthorized extraction of security camera footage triggered by alerts. Exploitation requires no authentication or user interaction and can lead to significant confidentiality breaches. Although no known exploits are reported in the wild yet, the vulnerability's ease of exploitation and the sensitivity of the data involved make it a critical concern for organizations using this product. European organizations relying on Davantis DFUSION for security monitoring are at risk of exposure of private surveillance footage, potentially impacting privacy compliance and operational security. Mitigation involves promptly updating to version 6.186.1 or later once available and implementing network-level access controls to restrict access to the vulnerable endpoints. Join the discussion | CVE Database V5 | 11/24/2025, 12:18:45 UTC Added: 11/24/2025, 12:37:31 UTC |
Showing 1 to 1 of 1 result