LSC Smart Connect Indoor PTZ Camera Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in the LSC Smart Connect Indoor PTZ Camera, specifically in versions through 7.6.32. The issue arises in the 'tuya_ipc_direct_connect' function of the 'anyka_ipc' process, where improper input validation allows arbitrary code execution. This exploitation occurs during the Wi-Fi configuration process when a specially crafted QR code is scanned by the camera.

Impact

Exploitation of this vulnerability allows for remote arbitrary code execution on the affected camera.

Reproduction

To reproduce this vulnerability, generate a QR code that includes malicious payloads in the Wi-Fi password field. Once the QR code is created, present it to the camera during its Wi-Fi setup process. The camera will scan the QR code and execute the embedded commands, such as creating a file in the '/tmp' directory.

Remediation

Users are advised to disable the QR code Wi-Fi configuration feature until an official patch is released. Additionally, firmware updates should be applied as they become available from the manufacturer.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.