PatchSiren cyber security CVE debrief
CVE-2025-47553 Digital zoom studio CVE debrief
A Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection, affecting versions from n/a through 12.25. The CVE record was published on 2026-01-06T17:15:44.070Z and has not been modified since then. The NVD entry is currently Deferred. Defenders should assess exposure and prioritize verification and potential updates. This vulnerability allows for Object Injection, which can lead to significant operational impacts if exploited. Verification of exposure in DZS Video Gallery installations is necessary, and defenders should assess the need for updates or mitigations.
- Vendor
- Digital zoom studio
- Product
- DZS Video Gallery
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-06
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-06
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for DZS Video Gallery installations should assess exposure and prioritize verification and potential updates. This includes operators, platform administrators, vulnerability management teams, and security teams who manage or use DZS Video Gallery. Verification of exposure in DZS Video Gallery installations is necessary, and defenders should assess the need for updates or mitigations due to the
Why it matters
Defenders should prioritize verifying exposure in their environments, especially those using DZS Video Gallery, and assess the need for updates or mitigations due to the Deserialization of Untrusted Data vulnerability allowing Object Injection.
- Verification of exposure in DZS Video Gallery installations is necessary
- Potential for Object Injection attacks requires defensive measures
- Defenders should assess the need for updates or mitigations
Technical summary
The DZS Video Gallery plugin has a Deserialization of Untrusted Data vulnerability allowing Object Injection, affecting versions from n/a through 12.25. This vulnerability can lead to Object Injection attacks, which require defensive measures. Defenders should prioritize verifying exposure in their environments, especially those using DZS Video Gallery, and assess the need for updates or mitigations.
Defensive priority
Defenders should prioritize verifying exposure in their environments, especially those using DZS Video Gallery, and assess the need for updates or mitigations.
Recommended defensive actions
- Verify if DZS Video Gallery versions prior to 12.25 are in use and assess exposure
- Consider updating to a version that addresses the vulnerability, if available
- Monitor for potential exploitation attempts
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability, with the NVD entry currently marked as Deferred. There is no detailed information on the exploitation of this vulnerability in the wild or any known affected systems beyond the version range provided. Defenders should verify if DZS Video Gallery versions prior to 12.25 are in use and assess exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-47553 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-47553
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-47553 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-47553
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.