Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
aziot-cctv-cve-2025-50777 — CVE-2025-50777: Root Access and Plaintext Credential Exposure in AZIOT Smart CCTV | Kitploit
Tools/GitHubGitHub/veereshgadige/aziot-cctv-cve-2025-50777
Embedded Systems SecurityPrivilege EscalationIoT SecurityVulnerability AnalysisExploitationInformation GatheringHardware HackingHardware SecurityPapers & Research

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Learning & Education
Firmware Analysis
GitHubveereshgadige/aziot-cctv-cve-2025-50777

aziot-cctv-cve-2025-50777

CVE-2025-50777: Root Access and Plaintext Credential Exposure in AZIOT Smart CCTV

View Repository
191 year agoNot yet reviewed

aziot-cctv-cve-2025-50777

CVE-2025-50777: Root Access and Plaintext Credential Exposure in AZIOT Smart CCTV

Summary

A local access control vulnerability (CVE-2025-50777) has been identified in the firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (Firmware Version V1.00.02). This flaw allows attackers with physical or local network access to gain unauthorized root shell access and extract sensitive credentials stored in plaintext. The vulnerability was discovered during a security assessment of the device’s firmware.


CVE ID

CVE-2025-50777 (currently RESERVED)


Affected Product

  • Vendor: AZIOT
  • Product: 2MP Full HD Smart Wi-Fi CCTV Home Security Camera
  • Firmware Version: V1.00.02
  • Storage: 128GB, 1 Channel

Vulnerability Details

During firmware analysis and UART access testing, the following issues were identified:

  • The device allows bypassing boot-level authentication via UART console using insecure bootloader and init script misconfigurations.
  • Once root access is gained, the file system reveals sensitive credentials in plaintext, including:
    • Wi-Fi SSID and password
    • ONVIF service authentication credentials

No encryption, access control, or secure storage mechanisms protect these credentials in the current firmware.


Impact

TypeDescription
Access VectorLocal (via UART interface or firmware extraction)

Recommendations

Until a vendor patch is made available, users are advised to:

  • Monitor for unusual ONVIF or RTSP activity
  • Disable ONVIF if not used
  • Encrypt all sensitive data in storage and transit

Discoverer

Gadige Veeresh
Embedded Security Researcher
LinkedIn


Disclosure Timeline

DateEvent
2025-04-27Vulnerability discovered
2025-04-28Responsible disclosure attempt sent to vendor
2025-07-15CVE-2025-50777 reserved by MITRE
2025-07-23Public disclosure on GitHub

Reference

  • http://aziot.com – Vendor website

Legal Note

This disclosure is for educational and research purposes only. The author does not assume responsibility for any misuse of this information.

Download Tool
Privilege Escalation
Yes – Root shell access is obtained
Information DisclosureYes – Plaintext credentials exposed
Risk LevelHigh – Enables full device compromise and lateral movement in network