7.5

CVE-2025-63209

Exploit
The ELCA Star Transmitter Remote Control firmware 1.25 for STAR150, BP1000, STAR300, STAR2000, STAR1000, STAR500, and possibly other models, contains an information disclosure vulnerability allowing unauthenticated attackers to retrieve admin credentials and system settings via an unprotected /setup.xml endpoint. The admin password is stored in plaintext under the <p05> XML tag, potentially leading to remote compromise of the transmitter system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ElcaradioStar150 Firmware Version1.25
   ElcaradioStar150 Version-
ElcaradioBp1000 Firmware Version1.25
   ElcaradioBp1000 Version-
ElcaradioStar300 Firmware Version1.25
   ElcaradioStar300 Version-
ElcaradioStar2000 Firmware Version1.25
   ElcaradioStar2000 Version-
ElcaradioStar1000 Firmware Version1.25
   ElcaradioStar1000 Version-
ElcaradioStar500 Firmware Version1.25
   ElcaradioStar500 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.08% 0.228
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.