CVE-2025-6951 Overview
CVE-2025-6951 affects the SAFECAM X300 IP camera through firmware version 20250611. The vulnerability resides in the FTP service, which ships with default credentials that remain active unless the operator changes them. An attacker on the adjacent network can authenticate to the FTP service using known defaults and access data exposed through that service. The weakness is classified under [CWE-1392: Use of Default Credentials]. Public disclosure occurred without vendor coordination, as the maintainer did not respond to the researcher. Technical details are published through the GitHub SAFECAM Project and VulDB entry #314488.
Critical Impact
An adjacent-network attacker can log in to the SAFECAM X300 FTP service using default credentials and access resources exposed by that service without any user interaction.
Affected Products
- SAFECAM X300 firmware versions up to and including 20250611
- FTP Service component bundled with SAFECAM X300
- Deployments where default FTP credentials have not been rotated
Discovery Timeline
- 2025-07-01 - CVE-2025-6951 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-6951
Vulnerability Analysis
The SAFECAM X300 ships with a File Transfer Protocol (FTP) service that is enabled by default and protected only by static vendor-supplied credentials. Any user who knows those credentials and can reach the device on the local network can authenticate successfully. Because the credentials are embedded in the shipped configuration and documented through publicly accessible references, the barrier to access is effectively removed once an attacker is on the same network segment.
The exploit is described publicly on the researcher's GitHub SAFECAM Project page. The vendor was notified before disclosure but did not respond, so no coordinated fix is available. The practical impact is limited to the confidentiality of data served by the FTP endpoint on the camera, but that data may include captured footage, configuration files, or logs depending on deployment.
Root Cause
The root cause is the shipment of the FTP service with hardcoded or default login credentials and the absence of a forced credential-change workflow during initial setup. This matches [CWE-1392: Use of Default Credentials]. Operators who do not manually rotate the FTP password inherit the vulnerable state directly from the factory configuration.
Attack Vector
Exploitation requires adjacency to the camera, meaning the attacker must reach the device on the same local network, Wi-Fi segment, or VLAN. The attacker initiates a standard FTP session against the device, supplies the documented default username and password, and gains the privileges associated with that account. No vulnerability chaining, memory corruption, or user interaction is required.
No verified exploit code is reproduced here. See the GitHub SAFECAM Project for the researcher's technical write-up.
Detection Methods for CVE-2025-6951
Indicators of Compromise
- Successful FTP authentication events to SAFECAM X300 devices originating from unexpected internal hosts
- FTP sessions using the vendor-default username on camera IP addresses
- Outbound FTP data transfers from camera devices to workstations or servers not involved in video management
- Unexpected LIST, RETR, or STOR commands recorded in network sensor logs for camera endpoints
Detection Strategies
- Inspect network flows for TCP port 21 traffic directed at camera subnets and alert when authentication succeeds from non-administrative hosts
- Deploy network intrusion detection signatures that flag FTP logins containing known SAFECAM default usernames
- Correlate camera FTP session metadata with asset inventory to identify unauthorized clients
Monitoring Recommendations
- Forward switch and firewall logs covering camera VLANs into a centralized logging platform for retention and search
- Baseline normal FTP activity for each SAFECAM X300 and alert on deviations in client source, time of day, or data volume
- Review authentication logs on the camera, if accessible, and export them to a SIEM for correlation with other network events
How to Mitigate CVE-2025-6951
Immediate Actions Required
- Change the default FTP username and password on every SAFECAM X300 device to a unique, high-entropy credential
- Disable the FTP service entirely if it is not required for operations
- Place SAFECAM X300 devices on an isolated VLAN with strict access control lists limiting which hosts can reach port 21
- Audit historical network logs for prior unauthorized FTP sessions to the affected cameras
Patch Information
No vendor patch is available. The vendor was contacted by the researcher before disclosure but did not respond. Operators should treat affected devices as unsupported for this issue and apply compensating controls. Monitor the VulDB entry #314488 for any future vendor response.
Workarounds
- Block inbound TCP port 21 to camera subnets at the firewall and permit only approved management hosts
- Enforce network segmentation that prevents guest, user, or IoT segments from reaching the camera management network
- Replace unsupported SAFECAM X300 devices with cameras from vendors that provide coordinated vulnerability response
- Rotate FTP credentials on a defined schedule and verify the change with an authenticated test session
# Example firewall rule to restrict FTP access to the camera subnet
# Replace 10.10.20.0/24 with your camera subnet and 10.10.5.10 with your approved management host
iptables -A FORWARD -p tcp -s 10.10.5.10 -d 10.10.20.0/24 --dport 21 -j ACCEPT
iptables -A FORWARD -p tcp -d 10.10.20.0/24 --dport 21 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.