CVE-2025-6532 MEDIUM

CVE-2025-6532: NOYAFA/Xiami LF9 Pro RTSP Live Video Stream Endpoint access control

Vendor Noyafa
Product LF9 Pro
Weakness CWE-284
Published June 24, 2025
Last update June 25, 2025

CVSS base score

5.3/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A vulnerability classified as problematic was found in NOYAFA/Xiami LF9 Pro up to 20250611. Affected by this vulnerability is an unknown functionality of the component RTSP Live Video Stream Endpoint. The manipulation leads to improper access controls. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. This dashcam is distributed by multiple resellers and different names.

Key dates

02Disclosure timeline

June 24, 2025 CVE published
June 25, 2025 Record updated