CVE-2025-9983: Lack of Authentication for RTSP stream
GALAYOU G2 cameras stream video output via RTSP streams. By default these streams are protected by randomly generated credentials. However these credentials are not required to access the stream. Changing these values does not change camera's behavior.
The vendor did not respond in any way. Only version 11.100001.01.28 was tested, other versions might also be vulnerable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9983?
CVE-2025-9983 has been classified as a medium severity vulnerability due to unauthorized access to video streams.
How do I fix CVE-2025-9983?
There is currently no fix for CVE-2025-9983, as changing the random credentials does not restrict access to the camera streams.
What impact does CVE-2025-9983 have on privacy?
CVE-2025-9983 could lead to unauthorized viewing of private video feeds from GALAYOU G2 cameras.
Is it safe to use GALAYOU G2 cameras with CVE-2025-9983?
Using GALAYOU G2 cameras poses a security risk due to the lack of effective authentication for RTSP streams.
Are older versions of the GALAYOU G2 camera affected by CVE-2025-9983?
Yes, all versions of the GALAYOU G2 camera are susceptible to CVE-2025-9983 as the vulnerability is inherent in the product design.