Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Longwatch RCE Vulnerability Let Attackers Execute Remote Code With Elevated Privileges

A critical vulnerability has been identified in the Longwatch video surveillance system by Industrial Video & Control, permitting remote code execution with elevated privileges.

A critical vulnerability has been identified in the Longwatch video surveillance system by Industrial Video & Control, permitting remote code execution with elevated privileges.

The vulnerability, designated CVE-2025-13658, affects Longwatch versions 6.309 through 6.334. It holds a severe CVSS v4 score of 9.3, indicating high risk.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory on Tue, Dec 2, 2025, alerting organizations to the potential threat.

The flaw is due to inadequate code-injection controls , enabling unauthorized attackers to exploit the system via simple HTTP GET requests. The absence of code-signing and execution safeguards permits the injection and execution of arbitrary code without login credentials.

The vulnerability grants SYSTEM-level privileges, the highest permission level in Windows environments, allowing attackers full control over the compromised system. Potential implications include accessing sensitive surveillance feeds, altering configurations, or using the system to launch further attacks.

Feature Description

The vulnerability, designated CVE-2025-13658, affects Longwatch versions 6.309 through 6.334.
Aiden Sinclair · Thehackingpost

CVE ID CVE-2025-13658

Vendor Industrial Video & Control

Equipment Longwatch

Vulnerability Improper Control of Generation of Code ('Code Injection')

Affected Versions 6.309 to 6.334

Advertisement

CVSS v4 Score 9.3

Industrial Video & Control has released version 6.335 to rectify the vulnerability. Users of affected versions should update promptly to the patched version.

CISA recommends additional measures, including isolating control systems from the internet, implementing firewalls between control and business networks, and using secure VPNs for remote access.

No public exploitation attempts have been reported as of now. However, due to the vulnerability's severity and ease of exploitation, immediate patching is imperative for affected organizations.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories