CVE-2025-8075: Improper Input Validation
Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered that validation of incoming XML format request messages is inadequate. This vulnerability could allow an attacker to XSS on the user's browser. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8075?
CVE-2025-8075 has been rated with a critical severity level due to the potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2025-8075?
To fix CVE-2025-8075, update the Hanwha Vision firmware to the versions that are not affected by this vulnerability.
What types of software are affected by CVE-2025-8075?
CVE-2025-8075 affects various models of Hanwha Vision surveillance camera firmware, specifically versions prior to the specified thresholds.
Can I exploit CVE-2025-8075 to gain access to a system?
Yes, an attacker could exploit CVE-2025-8075 to execute a cross-site scripting attack, potentially gaining unauthorized access.
What should I do if I cannot update the firmware for CVE-2025-8075?
If you cannot update the firmware for CVE-2025-8075, apply stringent access controls and monitoring to mitigate potential risks.