A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of the file /onvif/device_service of the component ONVIF PTZ Control Interface. The manipulation leads to improper access controls. The attack requires being on the local network. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Thu, 18 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Shenzhenningyuandatechnology
Shenzhenningyuandatechnology tc155
Shenzhenningyuandatechnology tc155 Firmware
CPEs cpe:2.3:h:shenzhenningyuandatechnology:tc155:-:*:*:*:*:*:*:*
cpe:2.3:o:shenzhenningyuandatechnology:tc155_firmware:57.0.2.0:*:*:*:*:*:*:*
Vendors & Products Shenzhenningyuandatechnology
Shenzhenningyuandatechnology tc155
Shenzhenningyuandatechnology tc155 Firmware

Tue, 16 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Ningyuanda
Ningyuanda tc155
Vendors & Products Ningyuanda
Ningyuanda tc155

Tue, 16 Dec 2025 03:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of the file /onvif/device_service of the component ONVIF PTZ Control Interface. The manipulation leads to improper access controls. The attack requires being on the local network. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Ningyuanda TC155 ONVIF PTZ Control device_service access control
Weaknesses CWE-266
CWE-284
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:A/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-12-16T03:02:10.508Z

Updated: 2025-12-16T20:48:27.694Z

Reserved: 2025-12-15T20:39:20.608Z

Link: CVE-2025-14749

cve-icon Vulnrichment

Updated: 2025-12-16T20:48:17.843Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-16T03:15:57.840

Modified: 2025-12-18T21:24:34.693

Link: CVE-2025-14749

cve-icon Redhat

No data.