Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

No Patch for Flaw Exposing Hundreds of LG Cameras to Remote Hacking

Posted on July 25, 2025July 25, 2025 By CWS

Lots of of LG safety cameras are weak to distant hacking resulting from a not too long ago found flaw and they won’t obtain a patch.

The cybersecurity company CISA revealed on Thursday that LG Innotek LNV5110R cameras are affected by an authentication bypass vulnerability that may enable an attacker to realize administrative entry to the machine.

The flaw, tracked as CVE-2025-7742 and assigned a ‘excessive severity’ ranking, can enable an attacker to add an HTTP POST request to the machine’s non-volatile storage, which can lead to distant code execution with elevated privileges, based on CISA.

LG Innotek has been notified, however stated the vulnerability can’t be patched because the product has reached finish of life.

Souvik Kandar, the MicroSec researcher credited by CISA for reporting the vulnerability, instructed SecurityWeek there are roughly 1,300 cameras which can be uncovered to the web and which may be remotely hacked.

The researcher stated an attacker might exploit the vulnerability to realize entry to reside streams, disrupt the digicam, and for different malicious actions. 

“It is a full unauthenticated distant code execution vulnerability,” Kandar defined. “An attacker can add a reverse shell with none login, acquire administrative privileges, execute arbitrary Linux instructions, and use the machine as a launching pad to pivot into inside networks.”

CISA stated the impacted product is used worldwide, together with within the industrial services essential infrastructure sector. Commercial. Scroll to proceed studying.

SecurityWeek has reached out to LG Innotek for remark and can replace this text if the corporate responds. 

Kandar stated he reported 50 vulnerabilities this 12 months, together with in good climate techniques, seismic sensors, marine techniques, routers, and OT gadgets, together with AutomationDirect, Instantel and Lantronix merchandise designed for industrial environments. 

Associated: 40,000 Safety Cameras Uncovered to Distant Hacking

Associated: Vulnerabilities Permit Distant Hacking of Inaba Plant Monitoring Cameras

Associated: Unpatched Edimax Digital camera Flaw Exploited Since at Least Could 2024

Security Week News Tags:Cameras, Exposing, Flaw, Hacking, Hundreds, Patch, Remote

Post navigation

Previous Post: Malicious Android Apps Mimic as Popular Indian Banking Apps Steal Login Credentials
Next Post: Chinese Spies Target Networking and Virtualization Flaws to Breach Isolated Environments

Related Posts

Trump Cybersecurity Executive Order Targets Digital Identity, Sanctions Policies Security Week News
Microsoft Offers Free Windows 10 Extended Security Update Options as EOS Nears Security Week News
Wiz Warns of Ongoing Exploitation of Recent Ivanti Vulnerabilities Security Week News
Code Execution Flaws Haunt Adobe Acrobat Reader, Adobe Commerce Security Week News
LevelBlue to Acquire Trustwave to Create Major MSSP Security Week News
Webinar Today: Redefining Vulnerability Management With Exposure Validation Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Salat Stealer Exfiltrates Browser Credentials Via Sophisticated C2 Infrastructure
  • Critical Ivanti Endpoint Manager Vulnerabilities Let Attackers Execute Remote Code
  • Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks
  • Exposed Docker APIs Likely Exploited to Build Botnet
  • SAP Patches Critical NetWeaver Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Salat Stealer Exfiltrates Browser Credentials Via Sophisticated C2 Infrastructure
  • Critical Ivanti Endpoint Manager Vulnerabilities Let Attackers Execute Remote Code
  • Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks
  • Exposed Docker APIs Likely Exploited to Build Botnet
  • SAP Patches Critical NetWeaver Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News