IDIS A.I CyberSecurity Scoring
IDIS
Company Information
Website:https://http://www.idisglobal.com
Employees number:231
Number of followers:6,686
NAICS:335
Industry Type:Appliances, Electrical, and Electronics Manufacturing
Homepage:idisglobal.com
IDIS Risk Score (AI oriented)
Between 750 and 799
IDISAppliances, Electrical, and Electronics Manufacturing
Updated:
05/04/2026
05/04/2026
753/1000
Fair
Baa
IDIS Global Score (TPRM)
xxxx
IDISAppliances, Electrical, and Electronics Manufacturing
Score locked

IDISFair
Current Score
753Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
753
JUNE 2026
753
MAY 2026
753
APRIL 2026
753
MARCH 2026
753
FEBRUARY 2026
753
JANUARY 2026
753
DECEMBER 2025
753
NOVEMBER 2025
752
OCTOBER 2025
752
SEPTEMBER 2025
752
AUGUST 2025
752
JANUARY 2025
748
Vulnerability
01 Jan 2025 • IDIS
IDIS: Critical IDIS IP Camera Vulnerability Allows Full Computer Compromise with One-Click Exploit
Critical One-Click RCE Vulnerability in IDIS Cloud Manager Exposes Surveillance Systems
751
CRITICAL-3
IDI1769618820
Critical One-Click RCE Vulnerability in IDIS Cloud Manager Exposes Surveillance Systems
A severe vulnerability in IDIS Cloud Manager (ICM) Viewer (CVE-2025-12556, CVSS 8.7) allows attackers to achieve remote code execution (RCE) with a single click, compromising Windows systems used to monitor IDIS IP cameras. The flaw, discovered by security researchers, stems from improper input validation in the ICM Viewer’s WebSocket communication, enabling malicious command-line flag injection.
### How the Attack Works
The ICM Viewer, a Windows application for accessing live and recorded surveillance feeds via IDIS’s cloud platform, relies on a local service (CWGService.exe) listening on ws://localhost:16140. When a user clicks "Run Viewer" in the web dashboard, the service launches WCMViewer.exe with parameters including a URL passed without sufficient sanitization.
Attackers can exploit this by:
1. Tricking a user into visiting a malicious webpage containing JavaScript that opens a WebSocket connection to localhost:16140.
2. Injecting malicious Chromium command-line flags (e.g., `--utility-cmd-prefix`) into the viewer’s launch parameters, as WCMViewer.exe is built on the Chromium Embedded Framework (CEF).
3. Executing arbitrary code on the victim’s system, as demonstrated by researchers who spawned notepad.exe as a proof of concept.
### Impact & Risks
- One-click RCE: No user interaction beyond clicking a link is required.
- Full system compromise: Attackers gain control of the Windows host managing IDIS surveillance, potentially enabling lateral movement within networks.
- Exposure of critical infrastructure: Compromised systems could provide access to other surveillance assets or sensitive endpoints.
### Root Causes
The vulnerability arises from multiple design flaws:
- No origin validation (missing CORS checks on the local WebSocket).
- Hard-coded encryption key for WebSocket messages.
- Unsanitized command-line arguments passed to WCMViewer.exe.
- Insufficient parameter validation before CEF execution.
### Mitigation & Response
IDIS has released ICM Viewer version 1.7.1 to address the issue, urging customers to upgrade immediately or uninstall the software if patching is not feasible. The Cybersecurity and Infrastructure Security Agency (CISA) has also highlighted the risk, emphasizing the need for organizations to review exposed surveillance management systems and harden local services.
The flaw underscores the risks of cloud-connected security tools with inadequate input validation, particularly in critical infrastructure environments.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for IDIS ??
What was IDIS's A.I Rankiteo Cyber Score in June 2026 ??
What was IDIS's A.I Rankiteo Cyber Score in May 2026 ??
What was IDIS's A.I Rankiteo Cyber Score in April 2026 ??
What was IDIS's A.I Rankiteo Cyber Score in March 2026 ??
What was IDIS's A.I Rankiteo Cyber Score in February 2026 ??
What was IDIS's A.I Rankiteo Cyber Score in January 2026 ??
What was IDIS's A.I Rankiteo Cyber Score in December 2025 ??
What was IDIS's A.I Rankiteo Cyber Score in November 2025 ??
What was IDIS's A.I Rankiteo Cyber Score in October 2025 ??
What was IDIS's A.I Rankiteo Cyber Score in September 2025 ??
What was IDIS's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on IDIS's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with IDIS ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view IDIS's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?