CISA released advisories detailing critical vulnerabilities affecting the Festo LX Appliance and multiple India-based CCTV cameras. The Festo LX Appliance was found to have a cross-site scripting (XSS) vulnerability (CVE-2021-23414) in versions prior to June 2023, which could allow a high-privilege user to craft a malicious course and execute arbitrary code via improper input neutralization in the video.js package. Festo coordinated the disclosure with CERT@VDE and recommends updating affected appliances to the latest version by contacting their services department. This vulnerability impacts sectors such as commercial facilities, communications, critical manufacturing, and energy worldwide.
Separately, a missing authentication vulnerability (CVE-2025-13607) was identified in D-Link (India) CCTV camera model DCS-F5614-L1 (versions v1.03.038 and prior), with similar issues suspected in Sparsh Securitech and Securus CCTV products. This flaw allows remote attackers to access camera configuration information, including account credentials, without authentication, posing a significant risk of information disclosure. The affected products are primarily deployed in India, and while D-Link is headquartered in Taiwan, the other vendors are based in India. Securus CCTV and Sparsh Securitech did not respond to CISA's coordination requests, and users are urged to review the advisories for mitigation steps.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
CISA announced three Industrial Control Systems advisories covering U-Boot, Festo LX Appliance, and multiple India-based CCTV cameras. The advisories provided technical details and mitigation guidance for the identified vulnerabilities.
CISA published advisory ICSA-25-343-03 disclosing CVE-2025-13607 in multiple India-based CCTV cameras and recommending mitigations such as reducing network exposure and securing remote access. CISA noted no public exploitation had been reported at the time of release, and that Sparsh Securitech and Securus CCTV had not responded to coordination requests.
D-Link issued a security advisory and software update for the DCS-F5614-L1 camera model to address CVE-2025-13607. The issue affects version 1.03.038 and prior and was rated critical.
Souvik Kandar reported a critical missing-authentication vulnerability, later assigned CVE-2025-13607, affecting multiple India-based CCTV cameras to CISA. The flaw allows unauthenticated access to camera configuration data, including account credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.