Longwatch devices are specialized video surveillance and remote monitoring systems, often deployed in critical infrastructure and Industrial Control System (ICS) environments. Their role in monitoring sensitive physical processes means that a compromise can have concrete physical consequences in the real world, beyond the typical loss of data.
The impact of this vulnerability is an unauthenticated Remote Code Execution (RCE) with SYSTEM-level privileges. This represents a total compromise of the device’s confidentiality, integrity, and availability. Due to the simplicity of the exploit—which requires only a specially crafted HTTP GET request—the barrier to entry for attackers is extremely low.
This vulnerability has been the subject of a CISA Industrial Control Systems (ICS) advisory, signaling a high level of concern for critical infrastructure owners. Given the public disclosure and widespread media attention, security teams should assume that malicious actors are actively searching for and exploiting exposed, unpatched Longwatch devices. Any Longwatch system accessible from the Internet is at immediate and critical risk.
| Product | Longwatch |
| Date | 2025-12-05 00:33:08 |
Technical Summary
The root cause of CVE-2025-13658 is a severe input validation error within the device’s web server. The vulnerability can be classified as a form of CWE-78: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’). The device exposes an HTTP endpoint that accepts GET requests, and certain parameters within the request are passed directly to the underlying operating system for execution without proper sanitization or validation.
The attack chain is as follows:
- An unauthenticated attacker identifies an exposed Longwatch device.
- The attacker constructs a single HTTP GET request containing OS commands embedded within a specific parameter sent to the vulnerable endpoint.
- The device’s web service fails to validate the input and passes the malicious string to a system shell.
- The embedded command is executed with SYSTEM-level privileges, granting the attacker full control over the device.
The fundamental security failure is the lack of basic controls such as input sanitization, code signing, and execution validation. No specific affected versions have been made public; therefore, all Longwatch devices exposing an HTTP interface must be considered vulnerable until a patch is applied. A successful attacker can exfiltrate sensitive data, manipulate device operation, or use the compromised system as a foothold to attack deeper into the Operational Technology (OT) network.
Recommendations
- Patch immediately: Contact the vendor to obtain and apply the security updates or firmware patches necessary to fix this vulnerability. There is no public information on versions, so a direct request to the vendor is required.
- Mitigations:
- Immediately remove any Longwatch device from direct Internet exposure.
- Place devices behind a firewall or VPN and strictly control access to the HTTP management interface. Allow only trusted IP addresses.
- If possible, disable the HTTP interface if it is not necessary for business operations.
- Threat Hunting & Monitoring:
- Analyze firewall and web server logs for incoming GET requests to the Longwatch device that contain unusual characters, shell commands (e.g.,
wget,curl,chmod), or IP addresses in the parameters. - Monitor for any unexpected outbound network connections from Longwatch devices, as this could indicate that an attacker is establishing a reverse shell or exfiltrating data.
- Analyze firewall and web server logs for incoming GET requests to the Longwatch device that contain unusual characters, shell commands (e.g.,
- Incident Response:
- If a compromise is suspected, immediately isolate the affected device from the network to prevent lateral movement.
- Preserve logs, firmware, and a disk image of the device for forensic analysis.
- Assume that the attacker may have performed lateral movement and initiate a broader search for malicious activity within the network segment.
- Defense in Depth:
- Ensure that OT (Operational Technology) networks are properly segmented from corporate IT networks to contain any compromises.
- Implement a robust asset inventory and vulnerability management program to quickly identify at-risk ICS (Industrial Control Systems).
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
