216.73.217.22

CVE-2025-65212

· Published 06/01/2026 16:15 · Modified 06/01/2026 17:15

Labels: CVE-2025-65212 2026-01-06CVE-2025-65212CWE-565[email protected]

Essential information

Published
06/01/2026 16:15
Modified
06/01/2026 17:15
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the device's insufficient cookie verification, allowing an attacker to directly request the configuration file address and download the core configuration file without logging into the device management backend. By reading the corresponding username and self-decrypted MD5 password in the core configuration file, the attacker can directly log in to the backend, thereby bypassing the front-end backend login page.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
njhyst / hy511 poe core cpe:2.3:a:njhyst:hy511_poe_core:*:*:*:*:*:*:*:*
njhyst / plugin cpe:2.3:a:njhyst:plugin:*:*:*:*:*:*:*:*

References