# NVD CVE-2025-47819 - improper access control on gunshot device debug interface before 1.3 > *Audited source extract. The dossier was used only as a lead; the underlying source was independently acquired and checked on 2026-07-20.* ## Source metadata - **Publisher:** National Vulnerability Database / CVE Program - **Original dossier URL:** https://nvd.nist.gov/vuln/detail/CVE-2025-47819 - **Resolved/canonical URL used:** https://nvd.nist.gov/vuln/detail/CVE-2025-47819 - **Publication date:** 2025-06-27 - **Underlying event or version:** gunshot devices before 1.3 - **Archived:** 2026-07-20, from unauthenticated public access; no cookies, tokens, or login state retained - **Wayback snapshot:** save failed on 2026-07-20 after the archive service returned HTTP 403; retry pending ## Verification verdict **obsolete/version-specific** — CVE-2025-47819 supports the described gunshot devices before 1.3; debug-interface access control. The CNA description and NVD configuration range are not perfectly aligned for the gunshot-device boundary, so applicability must be confirmed against the exact model and firmware. No current fixed-version matrix was located, and absence from the CISA KEV catalog on July 20, 2026 does not mean unexploited. ## Claim boundary The catalog product name 'LPR 2.2 Camera' is not established as the same identifier as firmware through 2.2. ## Extract **CVE Program record:** CVE-2025-47819; state PUBLISHED; published 2025-06-27; last updated 2025-09-02. **Structured affected block (`containers.cna.affected`):** - Flock Safety / Gunshot Detection devices: status=affected; version=0; lessThan=1.3; versionType=custom **Narrative applicability boundary used in this audit:** gunshot devices before 1.3. When the structured affected block says `n/a`, the narrative build or application version is the controlling limit; it is not evidence about every deployed Flock device. **Publication-safe verification summary:** CVE-2025-47819 supports the described gunshot devices before 1.3; debug-interface access control. The CNA description and NVD configuration range are not perfectly aligned for the gunshot-device boundary, so applicability must be confirmed against the exact model and firmware. No current fixed-version matrix was located, and absence from the CISA KEV catalog on July 20, 2026 does not mean unexploited. **Classification and severity:** CWE-1191 On-Chip Debug and Test Interface With Improper Access Control; CVSS 6.4 MEDIUM. The CNA JSON is preserved as a companion to the NVD HTML. Operational endpoints, credentials, access paths, and exploitation instructions are deliberately omitted from this extract. **Additional identifier caveat:** The catalog product name 'LPR 2.2 Camera' is not established as the same identifier as firmware through 2.2. **Wayback failure**: The bounded Save Page Now pass stopped after the archive service returned HTTP 403 on the first request. This source was not individually retried; retry pending. ## Notes - Tier: 2 — Tier 2 primary public record. - Operational exploitation steps, credentials, endpoints, and targeting details are omitted from this markdown extract; the public originals are retained for defensive verification. - Cited by: see `citing_pages:` frontmatter; populated after wiki integration.