CVE-2025-12351: Inadequate access control measure allows unauthorized users to access restricted administrative functions
Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker could potentially exploit this vulnerability, leading to Privilege Escalation to admin privileged functionalities . Honeywell also recommends updating to the most recent version of this product, service or offering (S35 Pinhole/Kit Camera to version 2025.08.28, S35 AI Fisheye & Dual Sensor/Micro Dome/Full Color Eyeball & Bullet Camera to version 2025.08.22, S35 Thermal Camera to version 2025.08.26).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12351?
CVE-2025-12351 is classified as a high-severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2025-12351?
To fix CVE-2025-12351, update your Honeywell S35 Series Cameras to the latest version provided by Honeywell.
What are the affected products of CVE-2025-12351?
CVE-2025-12351 affects Honeywell S35 Pinhole/Kit Cameras, S35 AI Fisheye and Dual Sensor Cameras, and S35 Thermal Cameras.
What kind of vulnerability is CVE-2025-12351?
CVE-2025-12351 is an authorization bypass vulnerability that could allow an attacker to escalate privileges.
What happens if CVE-2025-12351 is exploited?
Exploitation of CVE-2025-12351 could lead to unauthorized access to admin functionalities within the affected cameras.