Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-6031— Insecure device pairing in end of life Amazon Cloud Cam

CVSS 7.5 · High EPSS 0.21% · P44
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-6031

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Insecure device pairing in end of life Amazon Cloud Cam
Source: NVD (National Vulnerability Database)
Vulnerability Description
Amazon Cloud Cam is a home security camera that was deprecated on December 2, 2022, is end of life, and is no longer actively supported. When a user powers on the Amazon Cloud Cam, the device attempts to connect to a remote service infrastructure that has been deprecated due to end-of-life status. The device defaults to a pairing status in which an arbitrary user can bypass SSL pinning to associate the device to an arbitrary network, allowing for network traffic interception and modification. We recommend customers discontinue usage of any remaining Amazon Cloud Cams.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
在过期或释放后对资源进行操作
Source: NVD (National Vulnerability Database)
Vulnerability Title
Amazon Cloud Cam 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Amazon Cloud Cam是Amazon的一款高清网络摄像头。 Amazon Cloud Cam存在安全漏洞,该漏洞源于设备默认配对状态允许绕过SSL固定,可能导致网络流量拦截和修改。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
AmazonCloud Cam 0 ~ * -

II. Public POCs for CVE-2025-6031

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-6031

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-6031

No comments yet


Leave a comment