CVE-2025-69986General

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A buffer overflow vulnerability exists in the ONVIF GetStreamUri function of LSC Indoor Camera V7.6.32. The application fails to validate the length of the Protocol parameter inside the Transport element. By sending a specially crafted SOAP request containing an oversized protocol string, an attacker can overflow the stack buffer, overwriting the return instruction pointer (RIP). This vulnerability allows for Denial of Service (DoS) via device crash or Remote Code Execution (RCE) in the context of the ONVIF service.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-25); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-25: 1Mentions · 2026-03-27: 103-2503-27
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-251
General1
2026-03-271
Disclosure1
Full discourse2 posts
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting LSC Indoor Camera (CVE-2025-69986) https://vuldb.com/?id.353910

    Post summary

    A new vulnerability (CVE-2025-69986) affecting LSC Indoor Camera has been added to VulDB; the post lacks technical details, PoC, patches, or exploitation reports.

    00000167
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-69986 LSC Smart Indoor Camera https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-69986

    Post summary

    The text only lists the CVE identifier, the affected product, and a link, with no further detail on exploitation, patching, or technical aspects.

    0000054
    4.0K followersView on X

Explore more