CVE-2019-9657: Alarm ADC-v522ir Firmware

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control, a different issue than CVE-2018-19588. This occurs because of incorrect protection of VPN certificates (used for initiating a VPN session to the Alarm.com infrastructure) on the local camera device.

Affected products

  • Alarm ADC-v522ir Firmware: version 0100b9 only

Published 2019-07-11. Last modified 2026-06-17.