CVE-2025-41016
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
24/11/2025
Last modified:
25/11/2025
Description
Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images and videos related to alarm events through access to “/alarms//”, where the “MEDIA” parameter can take the value of “snapshot” or “video.mp4”. These media files contain images recorded by security cameras in response to triggered alerts.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH



