CVE-2025-10265: Digiever|NVR - OS Command Injection
Published Sep 12, 2025
·Updated
Certain models of NVR developed by Digiever has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.
Affected Software
1 affected component
Digiever NVR
Remediation
Information
Update firmware version to x.x.x.79 and later
Event History
Sep 12, 2025
CVE Published
via MITRE·10:15 AM
Data Sourced
via MITRE·10:15 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
May 21, 57679
Event
via NVD·09:29 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-10265?
CVE-2025-10265 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2025-10265?
To fix CVE-2025-10265, update to the latest firmware version provided by Digiever for your NVR devices.
3
Who is affected by CVE-2025-10265?
CVE-2025-10265 affects certain models of Digiever NVR devices that are running vulnerable firmware.
4
Can CVE-2025-10265 be exploited remotely?
Yes, CVE-2025-10265 can be exploited remotely by unauthenticated attackers.
5
What type of vulnerability is CVE-2025-10265?
CVE-2025-10265 is classified as an OS Command Injection vulnerability.