9.8

CVE-2025-63207

Exploit
The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system compromise.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RvrTex30lcd/s Firmware Versiontexl-000400
   RvrTex30lcd/s Version-
RvrTex50lcd/s Firmware Versiontexl-000400
   RvrTex50lcd/s Version-
RvrTex100lcd/s Firmware Versiontexl-000400
   RvrTex100lcd/s Version-
RvrTex150lcd/s Firmware Versiontexl-000400
   RvrTex150lcd/s Version-
RvrTex300lcd Firmware Versiontexl-000400
   RvrTex300lcd Version-
RvrTex502lcd Firmware Versiontexl-000400
   RvrTex502lcd Version-
RvrTex702lcd Firmware Versiontexl-000400
   RvrTex702lcd Version-
RvrTex3500lcd Firmware Versiontexl-000400
   RvrTex3500lcd Version-
RvrTex1002lcd Firmware Versiontexl-000400
   RvrTex1002lcd Version-
RvrTex2000light Firmware Versiontexl-000400
   RvrTex2000light Version-
RvrTex2500lcd Firmware Versiontexl-000400
   RvrTex2500lcd Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.444
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.