CVE-2025-48735 MEDIUM

CVE-2025-48735

Vendor Bos
Product IP camera
Weakness CWE-89 · SQLi
Published May 23, 2025
Last update May 23, 2025

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

A SQL Injection issue in the request body processing in BOS IPCs with firmware 21.45.8.2.2_220219 before 21.45.8.2.3_230220 allows remote attackers to obtain sensitive information from the database via crafted input in the request body.

Key dates

02Disclosure timeline

May 23, 2025 CVE published
May 23, 2025 Record updated