# CVE-2025-10264

## Summary

- **CVE ID:** CVE-2025-10264
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-497
- **Published:** Sep 12, 2025
- **Last Modified:** Mar 12, 2026

## Description

Certain models of NVR developed by Digiever has an Exposure of Sensitive Information vulnerability, allowing unauthenticated remoter attackers to access the system configuration file and obtain plaintext credentials of the NVR and its connected cameras.

## Affected Products

- Digiever — DS-1200 (0)
- Digiever — DS-2100 Pro (0)
- Digiever — DS-2100 Pro+ (0)
- Digiever — DS-2100 UHD (0)
- Digiever — DS-2200 UHD (0)
- Digiever — DS-2200 UHD+ (0)
- Digiever — DS-4200 Pro (0)
- Digiever — DS-4200 Pro+ (0)
- Digiever — DS-4200 UHD (0)
- Digiever — DS-4200 UHD+ (0)
- Digiever — DS-4100-RM (0)
- Digiever — DS-4200-RM Pro+ (0)
- Digiever — DS-4200-RM UHD (0)
- Digiever — DS-8x00-RM Pro+ (0)
- Digiever — DS-8x00-SRM Pro+ (0)
- Digiever — DS-8x00-RM UHD (0)
- Digiever — DS-16x00-RM Pro+ (0)
- Digiever — DS-16x00-RM UHD (0)

## References

- [CNA](https://www.twcert.org.tw/tw/cp-132-10375-19f1e-1.html)
- [CNA](https://www.twcert.org.tw/en/cp-139-10376-a057c-2.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.48%
- **EPSS Percentile:** 40.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._