PT-2025-48772 · Unknown · Longwatch Devices

CVE-2025-13658

·

Published

2025-11-18

·

Updated

2026-01-08

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Longwatch version 6.309
Description A flaw in Longwatch devices permits unauthenticated HTTP GET requests to execute arbitrary code through an exposed endpoint. This is due to the lack of code signing and execution controls, leading to SYSTEM-level privileges. The issue allows for unauthenticated remote code execution.
Recommendations Segment and monitor Longwatch devices.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15403
CVE-2025-13658

Affected Products

Longwatch Devices