216.73.216.197

CVE-2025-27803

· Published 21/05/2025 12:16 · Modified 21/05/2025 20:24

Labels: CVE-2025-27803 2025-05-21551230f0-3615-47bd-b7cc-93e92e730bbfCVE-2025-27803CWE-306

Essential information

Published
21/05/2025 12:16
Modified
21/05/2025 20:24
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

CVSS metrics

Description

The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or potentially gain access to sensitive data.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
551230f0-3615-47bd-b7cc-93e92e730bbf
NVD
View on NVD

Affected products (CPE)

ProductCPE
* / devices cpe:2.3:a:*:devices:*:*:*:*:*:*:*:*

References