A critical unauthenticated SQL injection vulnerability, tracked as CVE-2025-12463, was discovered in Geutebruck G-Cam E-Series cameras. The flaw exists in the Group parameter of the /uapi-cgi/viewer/Param.cgi script and has been confirmed on the EFD-2130 camera running firmware version 1.12.0.19. The vulnerability is remotely exploitable and has been assigned a CVSS score of 9.8, indicating its severity and potential for exploitation without authentication.
Security researchers from Black Lantern Security demonstrated that the vulnerability could be exploited by injecting a URL-encoded XML CDATA block containing malicious SQL queries, allowing attackers to bypass the XML parser and manipulate database queries. Testing revealed that multiple versions of the G-Cam E-Series cameras are likely affected, though the full scope remains unconfirmed due to limited vendor response. The issue was reported to Geutebruck in July 2025, with public disclosure following a 90-day response window in November 2025.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Black Lantern Security published technical details confirming the vulnerability on a Geutebruck EFD-2130 camera running firmware 1.12.0.19. The write-up identified the issue as remotely exploitable without authentication and recommended firmware updates and safer SQL query handling.
A critical unauthenticated SQL injection vulnerability, CVE-2025-12463, was publicly disclosed for Geutebruck G-Cam E-Series cameras. The flaw affects the `/uapi-cgi/viewer/Param.cgi` endpoint via the `Group` parameter and was assigned a CVSS 9.8 score.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceblog.blacklanternsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.