216.73.217.22

CVE-2025-64385

· Published 31/10/2025 15:15 · Modified 31/10/2025 15:15

Labels: CVE-2025-64385 2025-10-3150b5080a-775f-442e-83b5-926b5ca517b6CVE-2025-64385CWE-20

Essential information

Published
31/10/2025 15:15
Modified
31/10/2025 15:15
Author
Creator
CVSS
9.2 CRITICAL (v3) 9.2 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The equipment initially can be configured using the manufacturer's application, by Wi-Fi, by the web server or with the manufacturer’s software. Using the manufacturer's software, the device can be configured via UDP. Analyzing this communication, it has been observed that any aspect of the initial configuration can be changed by means of the device's MAC without the need for authentication.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
50b5080a-775f-442e-83b5-926b5ca517b6
NVD
View on NVD

Affected products (CPE)

ProductCPE
manufacturer / application cpe:2.3:a:manufacturer:application:*:*:*:*:*:*:*:*

References