CVE-2025-25680: Lsc Ptz Dual Band Camera Firmware

High severity, CVSS 7.7. EPSS: 0.6% chance of exploitation in the next 30 days.

LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when a specially crafted QR code is presented to the camera.

Affected products

  • Lsc Ptz Dual Band Camera Firmware: version 7.6.32 only

Published 2025-03-11. Last modified 2026-06-17.