CVE-2025-12351: Inadequate access control measure allows unauthorized users to access restricted administrative functions

Published Oct 27, 2025
·
Updated

Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker could potentially exploit this vulnerability, leading to Privilege Escalation to admin privileged functionalities . Honeywell also recommends updating to the most recent version of this product, service or offering (S35 Pinhole/Kit Camera to version 2025.08.28, S35 AI Fisheye & Dual Sensor/Micro Dome/Full Color Eyeball & Bullet Camera to version 2025.08.22, S35 Thermal Camera to version 2025.08.26).

Affected Software

3 affected components
Honeywell S35 Pinhole/Kit Camera<2025.08.28
Honeywell S35 AI Fisheye & Dual Sensor/Micro Dome/Full Color Eyeball & Bullet Camera<2025.08.22
Honeywell S35 Thermal Camera<2025.08.26

Event History

Oct 27, 2025
CVE Published
via MITRE·03:03 PM
Data Sourced
via MITRE·03:03 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-12351?

CVE-2025-12351 is classified as a high-severity vulnerability due to the potential for privilege escalation.

2

How do I fix CVE-2025-12351?

To fix CVE-2025-12351, update your Honeywell S35 Series Cameras to the latest version provided by Honeywell.

3

What are the affected products of CVE-2025-12351?

CVE-2025-12351 affects Honeywell S35 Pinhole/Kit Cameras, S35 AI Fisheye and Dual Sensor Cameras, and S35 Thermal Cameras.

4

What kind of vulnerability is CVE-2025-12351?

CVE-2025-12351 is an authorization bypass vulnerability that could allow an attacker to escalate privileges.

5

What happens if CVE-2025-12351 is exploited?

Exploitation of CVE-2025-12351 could lead to unauthorized access to admin functionalities within the affected cameras.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203