CVE-2025-9983 - CVE House
Back to Database
Status published High CVE-2025-9983

Lack of Authentication for RTSP stream

Vulnerability Description

GALAYOU G2 cameras stream video output via RTSP streams. By default these streams are protected by randomly generated credentials. However these credentials are not required to access the stream. Changing these values does not change camera's behavior. The vendor did not respond in any way. Only version 11.100001.01.28 was tested, other versions might also be vulnerable.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9983

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Szymon Paszun

Affected Vendor

Affected Software

G2
Vulnerable Versions:
11.100001.01.28

Timeline

Official Publish: September 22nd, 2025
Last Modified: September 22nd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)