PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-47553 Digital zoom studio CVE debrief

A Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection, affecting versions from n/a through 12.25. The CVE record was published on 2026-01-06T17:15:44.070Z and has not been modified since then. The NVD entry is currently Deferred. Defenders should assess exposure and prioritize verification and potential updates. This vulnerability allows for Object Injection, which can lead to significant operational impacts if exploited. Verification of exposure in DZS Video Gallery installations is necessary, and defenders should assess the need for updates or mitigations.

Vendor
Digital zoom studio
Product
DZS Video Gallery
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-06
Original CVE updated
2026-09-30
Advisory published
2026-01-06
Advisory updated
2026-09-30

Who should care

Defenders responsible for DZS Video Gallery installations should assess exposure and prioritize verification and potential updates. This includes operators, platform administrators, vulnerability management teams, and security teams who manage or use DZS Video Gallery. Verification of exposure in DZS Video Gallery installations is necessary, and defenders should assess the need for updates or mitigations due to the

Why it matters

Defenders should prioritize verifying exposure in their environments, especially those using DZS Video Gallery, and assess the need for updates or mitigations due to the Deserialization of Untrusted Data vulnerability allowing Object Injection.

  • Verification of exposure in DZS Video Gallery installations is necessary
  • Potential for Object Injection attacks requires defensive measures
  • Defenders should assess the need for updates or mitigations

Technical summary

The DZS Video Gallery plugin has a Deserialization of Untrusted Data vulnerability allowing Object Injection, affecting versions from n/a through 12.25. This vulnerability can lead to Object Injection attacks, which require defensive measures. Defenders should prioritize verifying exposure in their environments, especially those using DZS Video Gallery, and assess the need for updates or mitigations.

Defensive priority

Defenders should prioritize verifying exposure in their environments, especially those using DZS Video Gallery, and assess the need for updates or mitigations.

Recommended defensive actions

  • Verify if DZS Video Gallery versions prior to 12.25 are in use and assess exposure
  • Consider updating to a version that addresses the vulnerability, if available
  • Monitor for potential exploitation attempts

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability, with the NVD entry currently marked as Deferred. There is no detailed information on the exploitation of this vulnerability in the wild or any known affected systems beyond the version range provided. Defenders should verify if DZS Video Gallery versions prior to 12.25 are in use and assess exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-47553 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-47553

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-47553 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-47553

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.