9.8

CVE-2025-63207

Exploit
The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system compromise.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rvr ≫ Tex30lcd/s Firmware Version texl-000400
   Rvr ≫ Tex30lcd/s Version -
Rvr ≫ Tex50lcd/s Firmware Version texl-000400
   Rvr ≫ Tex50lcd/s Version -
Rvr ≫ Tex100lcd/s Firmware Version texl-000400
   Rvr ≫ Tex100lcd/s Version -
Rvr ≫ Tex150lcd/s Firmware Version texl-000400
   Rvr ≫ Tex150lcd/s Version -
Rvr ≫ Tex300lcd Firmware Version texl-000400
   Rvr ≫ Tex300lcd Version -
Rvr ≫ Tex502lcd Firmware Version texl-000400
   Rvr ≫ Tex502lcd Version -
Rvr ≫ Tex702lcd Firmware Version texl-000400
   Rvr ≫ Tex702lcd Version -
Rvr ≫ Tex3500lcd Firmware Version texl-000400
   Rvr ≫ Tex3500lcd Version -
Rvr ≫ Tex1002lcd Firmware Version texl-000400
   Rvr ≫ Tex1002lcd Version -
Rvr ≫ Tex2000light Firmware Version texl-000400
   Rvr ≫ Tex2000light Version -
Rvr ≫ Tex2500lcd Firmware Version texl-000400
   Rvr ≫ Tex2500lcd Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.97% 0.934
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://www.rvr.it/en/
Product
https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63207_RVR%20Elettronica%20TEX%20Broken%20Access%20Control
Third Party Advisory
Exploit