CVE-2025-55810
Severity CVSS v4.0:
Pending analysis
Type:
CWE-434
Unrestricted Upload of File with Dangerous Type
Publication date:
13/11/2025
Last modified:
09/01/2026
Description
A vulnerability was found in Alaga Home Security WiFi Camera 3K (model S-CW2503C-H) with hardware version V03 and firmware version 1.4.2, which allows physical attackers to execute commands as root via script file with a specific name on a SD card.
Impact
Base Score 3.x
6.80
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:alagaai:s-cw2503c-h_firmware:1.4.2:*:*:*:*:*:*:* | ||
| cpe:2.3:h:alagaai:s-cw2503c-h:03:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



