Back to Database
Status published
High
CVE-2025-5113
Authenticated Remote Command Injection in Diviotec NBR IP Cameras
Vulnerability Description
The Diviotec professional series exposes a web interface. One endpoint is vulnerable to arbitrary command injection and hardcoded passwords are used.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-5113
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- ONEKEY Research Labs
Affected Vendor
Diviotec
View all reports →Affected Software
nbr222p, nbr222pv, nbr224p, nbr225p, nbr226p, nbf232p, nbf233p, ndr252p, ndr255p
Vulnerable Versions:
0
Timeline
Official Publish:
June 2nd, 2025
Last Modified:
June 2nd, 2025
Added to House:
July 22nd, 2026