Uniqcli Security
← Advisories
Mediumi-PROMay 30, 2025

Cross-Site Request Forgery in i-PRO WV-X/S/U Network Cameras (CVE-2025-36513)

NDAA Section 889: i-PRO (formerly Panasonic Security) is a Japanese-headquartered manufacturer and is not an NDAA Section 889 covered entity; its cameras are routinely specified for TAA/NDAA-compliant federal and DoD projects. This advisory does not affect that standing. This brand is a covered entity — replacing it, not just patching it, is the compliant path. See compliant replacements →

Summary

Affected i-PRO network cameras fail to validate the origin of state-changing web requests, so an authenticated administrator who is lured to a malicious page can have setting changes silently submitted to the camera on their behalf. The impact is limited to integrity of camera configuration and requires user interaction, which keeps this in the medium-severity band. It was reported through JVN by Nozomi Networks and fixed in the listed firmware releases.

Affected products

i-PRO Network Camera WV-X Series (firmware prior to 2.80)i-PRO Network Camera WV-S Series (firmware prior to 2.85)i-PRO Network Camera WV-U Series (firmware prior to 3.45)

Impact

An attacker can trick a logged-in operator into unknowingly altering camera settings via a forged cross-site request, potentially weakening device configuration or coverage. There is no direct data disclosure or denial of service, but configuration drift across many endpoints can erode monitoring reliability over time.

Remediation

Apply firmware 2.80 (WV-X), 2.85 (WV-S), or 3.45 (WV-U) or later per series. As defense in depth, keep camera web management off the public internet, require administrators to fully log out of camera UIs before browsing elsewhere, and segment camera management interfaces behind a jump host. Uniqcli Security can confirm which of your i-PRO series and firmware levels are exposed, batch-apply the updates, and lock down management-plane access so forged requests never reach the device.

Sources

Want us to handle it?

We patch, harden or replace affected devices and document the closeout.

Request a fleet scan
Stay ahead of it

Scan your fleet for vulnerable or banned devices.

Tell us what you need secured. We'll confirm compliance, design the system, and quote it — no payment up front.