GALAYOU G2 cameras expose RTSP video streams without authentication despite displaying…
GALAYOU G2 cameras expose RTSP video streams without authentication despite displaying randomly generated credentials, allowing unauthorized access to camera feeds.
CERT Polska coordinated the disclosure of CVE-2025-9983, an authentication bypass vulnerability in GALAYOU G2 camera software version 11.100001.01.28. The cameras stream video via RTSP and display randomly generated credentials that purportedly protect these streams. However, the vulnerability allows access to RTSP streams without requiring any authentication credentials whatsoever. Changing the displayed credentials does not alter the camera's behavior, meaning the authentication mechanism is effectively non-functional.
The vendor was notified but failed to respond to the disclosure. Other firmware versions may also be affected, though only version 11.100001.01.28 was confirmed vulnerable during testing. The vulnerability was responsibly reported by security researcher Szymon Paszun through CERT Polska's coordinated vulnerability disclosure process.
This vulnerability poses a significant privacy risk to users of GALAYOU G2 cameras, as unauthorized parties could access live video feeds without authentication. Organizations and individuals using these devices should consider disconnecting them from networks or implementing network-level access controls until a patch becomes available.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2025/09/CVE-2025-9983
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free