First published: Thu Apr 24 2025(Updated: )
Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., Ltd. surveillance cameras and recorders. This vulnerability allows a local authenticated attacker to use the authentication information from the last connected surveillance cameras and recorders.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
i-PRO Configuration Tool |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32730 has a high severity rating due to its potential to allow local authenticated attackers to exploit hard-coded cryptographic keys.
To fix CVE-2025-32730, update the i-PRO Configuration Tool to the latest version provided by i-PRO Co., Ltd. that addresses this vulnerability.
CVE-2025-32730 affects users of the i-PRO Configuration Tool used with i-PRO Co., Ltd. surveillance cameras and recorders.
CVE-2025-32730 can be exploited by local authenticated attackers who can access the system and utilize the hard-coded cryptographic key.
If CVE-2025-32730 is exploited, it could lead to unauthorized access to sensitive data or manipulation of the surveillance system.