
CVE-2025-50777: Root Access and Plaintext Credential Exposure in AZIOT Smart CCTV
A local access control vulnerability (CVE-2025-50777) has been identified in the firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (Firmware Version V1.00.02). This flaw allows attackers with physical or local network access to gain unauthorized root shell access and extract sensitive credentials stored in plaintext. The vulnerability was discovered during a security assessment of the device’s firmware.
CVE-2025-50777 (currently RESERVED)
During firmware analysis and UART access testing, the following issues were identified:
No encryption, access control, or secure storage mechanisms protect these credentials in the current firmware.
| Type | Description |
|---|---|
| Access Vector | Local (via UART interface or firmware extraction) |
Until a vendor patch is made available, users are advised to:
Gadige Veeresh
Embedded Security Researcher
LinkedIn
| Date | Event |
|---|---|
| 2025-04-27 | Vulnerability discovered |
| 2025-04-28 | Responsible disclosure attempt sent to vendor |
| 2025-07-15 | CVE-2025-50777 reserved by MITRE |
| 2025-07-23 | Public disclosure on GitHub |
This disclosure is for educational and research purposes only. The author does not assume responsibility for any misuse of this information.
| Privilege Escalation |
| Yes – Root shell access is obtained |
| Information Disclosure | Yes – Plaintext credentials exposed |
| Risk Level | High – Enables full device compromise and lateral movement in network |