BluramsCVEs & Vulnerabilities

5 CVEs affecting Blurams products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

dome flare 2dome flare firmware 2lumi security camera a31c 2lumi security camera a31c firmware 2a31c 1a31c firmware 1
CVE-2025-65397MEDIUM

An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacker with physical access to the device to execute arbitrary commands with root privileges, if file /opt/images/public_key.der is not present in the file system. The vulnerability can be triggered by providing a maliciously crafted auth.ini file on the device's SD card.

14 Jan 2026
6.8
CVSS
CVE-2025-65396MEDIUM

A vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically proximate attacker to hijack the boot mechanism and gain a bootloader shell via the UART interface. This is achieved by inducing a read error from the SPI flash memory during the boot, by shorting a data pin of the IC to ground. An attacker can then dump the entire firmware, leading to the disclosure of sensitive information including cryptographic keys and user configurations.

14 Jan 2026
6.1
CVSS
CVE-2025-63674MEDIUM

An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootloader on the SD card.

25 Nov 2025
6.8
CVSS
CVE-2023-51820MEDIUM

An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code.

2 Feb 2024
6.8
CVSS
CVE-2023-50488CRITICAL

An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code.

2 Feb 2024
9.8
CVSS
← PrevPage 1 / 1Next →
Blurams CVEs & Vulnerabilities — 5 Tracked