Skip to main content

CVE-2025-6951: SAFECAM X300 Authentication Bypass Vulnerability

CVE-2025-6951 is an authentication bypass flaw in SAFECAM X300 FTP Service caused by default credentials. Attackers on the local network can gain unauthorized access. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2025-6951 Overview

CVE-2025-6951 affects the SAFECAM X300 IP camera through firmware version 20250611. The vulnerability resides in the FTP service, which ships with default credentials that remain active unless the operator changes them. An attacker on the adjacent network can authenticate to the FTP service using known defaults and access data exposed through that service. The weakness is classified under [CWE-1392: Use of Default Credentials]. Public disclosure occurred without vendor coordination, as the maintainer did not respond to the researcher. Technical details are published through the GitHub SAFECAM Project and VulDB entry #314488.

Critical Impact

An adjacent-network attacker can log in to the SAFECAM X300 FTP service using default credentials and access resources exposed by that service without any user interaction.

Affected Products

  • SAFECAM X300 firmware versions up to and including 20250611
  • FTP Service component bundled with SAFECAM X300
  • Deployments where default FTP credentials have not been rotated

Discovery Timeline

  • 2025-07-01 - CVE-2025-6951 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-6951

Vulnerability Analysis

The SAFECAM X300 ships with a File Transfer Protocol (FTP) service that is enabled by default and protected only by static vendor-supplied credentials. Any user who knows those credentials and can reach the device on the local network can authenticate successfully. Because the credentials are embedded in the shipped configuration and documented through publicly accessible references, the barrier to access is effectively removed once an attacker is on the same network segment.

The exploit is described publicly on the researcher's GitHub SAFECAM Project page. The vendor was notified before disclosure but did not respond, so no coordinated fix is available. The practical impact is limited to the confidentiality of data served by the FTP endpoint on the camera, but that data may include captured footage, configuration files, or logs depending on deployment.

Root Cause

The root cause is the shipment of the FTP service with hardcoded or default login credentials and the absence of a forced credential-change workflow during initial setup. This matches [CWE-1392: Use of Default Credentials]. Operators who do not manually rotate the FTP password inherit the vulnerable state directly from the factory configuration.

Attack Vector

Exploitation requires adjacency to the camera, meaning the attacker must reach the device on the same local network, Wi-Fi segment, or VLAN. The attacker initiates a standard FTP session against the device, supplies the documented default username and password, and gains the privileges associated with that account. No vulnerability chaining, memory corruption, or user interaction is required.

No verified exploit code is reproduced here. See the GitHub SAFECAM Project for the researcher's technical write-up.

Detection Methods for CVE-2025-6951

Indicators of Compromise

  • Successful FTP authentication events to SAFECAM X300 devices originating from unexpected internal hosts
  • FTP sessions using the vendor-default username on camera IP addresses
  • Outbound FTP data transfers from camera devices to workstations or servers not involved in video management
  • Unexpected LIST, RETR, or STOR commands recorded in network sensor logs for camera endpoints

Detection Strategies

  • Inspect network flows for TCP port 21 traffic directed at camera subnets and alert when authentication succeeds from non-administrative hosts
  • Deploy network intrusion detection signatures that flag FTP logins containing known SAFECAM default usernames
  • Correlate camera FTP session metadata with asset inventory to identify unauthorized clients

Monitoring Recommendations

  • Forward switch and firewall logs covering camera VLANs into a centralized logging platform for retention and search
  • Baseline normal FTP activity for each SAFECAM X300 and alert on deviations in client source, time of day, or data volume
  • Review authentication logs on the camera, if accessible, and export them to a SIEM for correlation with other network events

How to Mitigate CVE-2025-6951

Immediate Actions Required

  • Change the default FTP username and password on every SAFECAM X300 device to a unique, high-entropy credential
  • Disable the FTP service entirely if it is not required for operations
  • Place SAFECAM X300 devices on an isolated VLAN with strict access control lists limiting which hosts can reach port 21
  • Audit historical network logs for prior unauthorized FTP sessions to the affected cameras

Patch Information

No vendor patch is available. The vendor was contacted by the researcher before disclosure but did not respond. Operators should treat affected devices as unsupported for this issue and apply compensating controls. Monitor the VulDB entry #314488 for any future vendor response.

Workarounds

  • Block inbound TCP port 21 to camera subnets at the firewall and permit only approved management hosts
  • Enforce network segmentation that prevents guest, user, or IoT segments from reaching the camera management network
  • Replace unsupported SAFECAM X300 devices with cameras from vendors that provide coordinated vulnerability response
  • Rotate FTP credentials on a defined schedule and verify the change with an authenticated test session
bash
# Example firewall rule to restrict FTP access to the camera subnet
# Replace 10.10.20.0/24 with your camera subnet and 10.10.5.10 with your approved management host
iptables -A FORWARD -p tcp -s 10.10.5.10 -d 10.10.20.0/24 --dport 21 -j ACCEPT
iptables -A FORWARD -p tcp -d 10.10.20.0/24 --dport 21 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.