A critical vulnerability, tracked as CVE-2025-13607, has been identified in multiple CCTV camera products, including those from D-Link India Limited, Sparsh Securitech, and Securus CCTV. The flaw arises from missing authentication for a critical function, allowing remote attackers to access sensitive camera configuration data and administrative account credentials simply by exploiting a vulnerable URL endpoint. The vulnerability is network-accessible, requires no user interaction or special privileges, and has been assigned a CVSS v4 score of 9.3 and CVSS v3 score of 9.4, indicating its severe risk to surveillance infrastructure. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding this issue, and D-Link has released security updates for affected devices, urging immediate patching and verification of firmware versions.
Successful exploitation of this vulnerability could enable attackers to hijack video feeds, steal credentials, and potentially compromise entire surveillance systems. The D-Link DCS-F5614-L1 camera model running firmware versions v1.03.038 and earlier is confirmed to be affected, while other models from Sparsh Securitech and Securus CCTV may also be vulnerable. Organizations using these products are strongly advised to apply available patches and review their camera deployments for exposure. The flaw's trivial exploitation path and the sensitive nature of the data at risk make prompt remediation critical for maintaining the integrity and confidentiality of video surveillance operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
CISA issued an alert for CVE-2025-13607 and advised organizations to patch affected devices, isolate them on networks, and restrict access. The guidance emphasized the risk to surveillance infrastructure despite no active exploitation being reported.
D-Link released a security update for the DCS-F5614-L1 camera model to address CVE-2025-13607. Other named vendors, including Sparsh Securitech and Securus CCTV, had not responded to coordination requests at the time of reporting.
Public proof-of-concept exploit code for CVE-2025-13607 was observed on GitHub, increasing the likelihood of exploitation. The references do not provide a more specific date than the disclosure timeframe.
A critical missing-authentication vulnerability, CVE-2025-13607, was disclosed affecting camera/CCTV products and enabling unauthenticated access to configuration data, video feeds, and account credentials. The issue was published by ICS-CERT/DHS and rated critical, with CVSS scores around 9.3-9.4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.