Longwatch RCE Vulnerability Let Attackers Execute Remote Code With Elevated Privileges
A critical vulnerability has been identified in the Longwatch video surveillance system by Industrial Video & Control, permitting remote code execution with elevated privileges.
A critical vulnerability has been identified in the Longwatch video surveillance system by Industrial Video & Control, permitting remote code execution with elevated privileges.
The vulnerability, designated CVE-2025-13658, affects Longwatch versions 6.309 through 6.334. It holds a severe CVSS v4 score of 9.3, indicating high risk.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory on Tue, Dec 2, 2025, alerting organizations to the potential threat.
The flaw is due to inadequate code-injection controls , enabling unauthorized attackers to exploit the system via simple HTTP GET requests. The absence of code-signing and execution safeguards permits the injection and execution of arbitrary code without login credentials.
The vulnerability grants SYSTEM-level privileges, the highest permission level in Windows environments, allowing attackers full control over the compromised system. Potential implications include accessing sensitive surveillance feeds, altering configurations, or using the system to launch further attacks.
Feature Description
The vulnerability, designated CVE-2025-13658, affects Longwatch versions 6.309 through 6.334.
CVE ID CVE-2025-13658
Vendor Industrial Video & Control
Equipment Longwatch
Vulnerability Improper Control of Generation of Code ('Code Injection')
Affected Versions 6.309 to 6.334
CVSS v4 Score 9.3
Industrial Video & Control has released version 6.335 to rectify the vulnerability. Users of affected versions should update promptly to the patched version.
CISA recommends additional measures, including isolating control systems from the internet, implementing firewalls between control and business networks, and using secure VPNs for remote access.
No public exploitation attempts have been reported as of now. However, due to the vulnerability's severity and ease of exploitation, immediate patching is imperative for affected organizations.
Based on reporting by Cyber Security News.
