Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
IDIS

IDIS Vendor Cyber Rating & Cyber Score

idisglobal.com

IDIS is a global security company that designs, develops, and manufactures delivers video solutions for a wide range of commercial and public sector markets. As the largest video surveillance manufacturer in South Korea, headquartered just outside of Seoul, and operating across 50 countries and 100+ strategic partners, IDIS is a world-leading total solution provider with more than two million recorders installed worldwide and over 17 million cameras utilizing IDIS technology. Celebrating over 25 years of innovation, IDIS has met the needs of an increasingly demanding security landscape since its founding in 1997. IDIS provides the benefit of an end-to-end, highest-quality surveillance solution at a low total cost of ownership. IDIS


IDIS A.I CyberSecurity Scoring

IDIS
Company Information
Website:https://http://www.idisglobal.com
Employees number:231
Number of followers:6,686
NAICS:335
Industry Type:Appliances, Electrical, and Electronics Manufacturing
Homepage:idisglobal.com
IDIS Risk Score (AI oriented)
Between 750 and 799
logo
IDISAppliances, Electrical, and Electronics Manufacturing
Updated:
05/04/2026
753/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
IDIS Global Score (TPRM)
xxxx
logo
IDISAppliances, Electrical, and Electronics Manufacturing
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

IDIS
IDISFair
Current Score
753Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
753Before Incident
JUNE 2026
753Before Incident
MAY 2026
753Before Incident
APRIL 2026
753Before Incident
MARCH 2026
753Before Incident
FEBRUARY 2026
753Before Incident
JANUARY 2026
753Before Incident
DECEMBER 2025
753Before Incident
NOVEMBER 2025
752Before Incident
OCTOBER 2025
752Before Incident
SEPTEMBER 2025
752Before Incident
AUGUST 2025
752Before Incident
JANUARY 2025
748Before Incident
Vulnerability
01 Jan 2025IDIS
IDIS: Critical IDIS IP Camera Vulnerability Allows Full Computer Compromise with One-Click Exploit

Critical One-Click RCE Vulnerability in IDIS Cloud Manager Exposes Surveillance Systems

751After Incident
CRITICAL-3
IDI1769618820
Critical One-Click RCE Vulnerability in IDIS Cloud Manager Exposes Surveillance Systems A severe vulnerability in IDIS Cloud Manager (ICM) Viewer (CVE-2025-12556, CVSS 8.7) allows attackers to achieve remote code execution (RCE) with a single click, compromising Windows systems used to monitor IDIS IP cameras. The flaw, discovered by security researchers, stems from improper input validation in the ICM Viewer’s WebSocket communication, enabling malicious command-line flag injection. ### How the Attack Works The ICM Viewer, a Windows application for accessing live and recorded surveillance feeds via IDIS’s cloud platform, relies on a local service (CWGService.exe) listening on ws://localhost:16140. When a user clicks "Run Viewer" in the web dashboard, the service launches WCMViewer.exe with parameters including a URL passed without sufficient sanitization. Attackers can exploit this by: 1. Tricking a user into visiting a malicious webpage containing JavaScript that opens a WebSocket connection to localhost:16140. 2. Injecting malicious Chromium command-line flags (e.g., `--utility-cmd-prefix`) into the viewer’s launch parameters, as WCMViewer.exe is built on the Chromium Embedded Framework (CEF). 3. Executing arbitrary code on the victim’s system, as demonstrated by researchers who spawned notepad.exe as a proof of concept. ### Impact & Risks - One-click RCE: No user interaction beyond clicking a link is required. - Full system compromise: Attackers gain control of the Windows host managing IDIS surveillance, potentially enabling lateral movement within networks. - Exposure of critical infrastructure: Compromised systems could provide access to other surveillance assets or sensitive endpoints. ### Root Causes The vulnerability arises from multiple design flaws: - No origin validation (missing CORS checks on the local WebSocket). - Hard-coded encryption key for WebSocket messages. - Unsanitized command-line arguments passed to WCMViewer.exe. - Insufficient parameter validation before CEF execution. ### Mitigation & Response IDIS has released ICM Viewer version 1.7.1 to address the issue, urging customers to upgrade immediately or uninstall the software if patching is not feasible. The Cybersecurity and Infrastructure Security Agency (CISA) has also highlighted the risk, emphasizing the need for organizations to review exposed surveillance management systems and harden local services. The flaw underscores the risks of cloud-connected security tools with inadequate input validation, particularly in critical infrastructure environments.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: Windows systems running IDIS Cloud Manager (ICM) ViewerOperational Impact: Full system compromise, potential lateral movement within networks

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for IDIS ?
?
What was IDIS's A.I Rankiteo Cyber Score in June 2026 ?
?
What was IDIS's A.I Rankiteo Cyber Score in May 2026 ?
?
What was IDIS's A.I Rankiteo Cyber Score in April 2026 ?
?
What was IDIS's A.I Rankiteo Cyber Score in March 2026 ?
?
What was IDIS's A.I Rankiteo Cyber Score in February 2026 ?
?
What was IDIS's A.I Rankiteo Cyber Score in January 2026 ?
?
What was IDIS's A.I Rankiteo Cyber Score in December 2025 ?
?
What was IDIS's A.I Rankiteo Cyber Score in November 2025 ?
?
What was IDIS's A.I Rankiteo Cyber Score in October 2025 ?
?
What was IDIS's A.I Rankiteo Cyber Score in September 2025 ?
?
What was IDIS's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on IDIS's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with IDIS ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view IDIS's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?