CVE-2025-12463

Publication date

2025-11-03 16:45:39

Family

BLSOPS

State

PUBLISHED

Description

An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` parameter in the `/uapi-cgi/viewer/Param.cgi` script. This has been confirmed on the EFD-2130 camera running firmware version 1.12.0.19.