CVE-2025-63296: Keruistore Kerui k259 Firmware

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot/update logic: during startup /usr/sbin/anyka_service.sh scans mounted TF/SD cards and, if /mnt/update.nor.sh is present, copies it to /tmp/net.sh and executes it as root.

Affected products

  • Keruistore Kerui k259 Firmware: version 33.53.87 only

Published 2025-11-10. Last modified 2026-06-17.