CVE-2025-12463 is an unauthenticated SQL injection vulnerability in Geutebruck G-Cam E-Series cameras. The flaw occurs when the camera's viewer API processes the Group request parameter without safely neutralizing SQL syntax. It has been confirmed on an EFD-2130 camera running firmware version 1.12.0.19.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, the expected impact includes high confidentiality, integrity, and availability consequences, including unauthorized access to sensitive configuration or stored data, tampering with application state, and possible service disruption. Depending on database privileges and product architecture, exploitation may also create opportunities for deeper system compromise through SQL-injection-related post-exploitation paths.If you can’t patch tonight, do this now.
/uapi-cgi/viewer/Param.cgi, to trusted administrative networks only. Do not expose affected devices directly to the public Internet. Place devices behind firewalls or VPNs, apply ACLs to limit reachable source IPs, and monitor HTTP requests for anomalous or SQL-injection-like input targeting the Group parameter. Where operationally feasible, disable unnecessary remote access paths and segment affected cameras from broader enterprise networks until patched firmware can be deployed.Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.