CVE-2018-25130: Beward R&d Co., Ltd Beward Intercom
Medium severity, CVSS 6.2. EPSS: 0.1% chance of exploitation in the next 30 days.
Beward Intercom 2.3.1 contains a credentials disclosure vulnerability that allows local attackers to access plain-text authentication credentials stored in an unencrypted database file. Attackers can read the BEWARD.INTERCOM.FDB file to extract usernames and passwords, enabling unauthorized access to IP cameras and door stations.
Affected products
- Beward R&d Co., Ltd Beward Intercom: version 2.3.1.34471 only; version 2.3.0 only; version 2.2.11 only; version 2.2.10.5 only; version 2.2.9 only; version 2.2.8.9 only; …
Published 2025-12-24. Last modified 2026-06-17.