← Zuruck zu CVEs
CVE-2025-27853
N/ABeschreibung
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU web site only performs authentication with the client within the client's browser. The WebSockets used to communicate with the WDU server do not enforce any authentication. An attacker may bypass all authentication mechanisms by directly utilizing the remote APIs available on the websocket.
CVE Details
CVSS v3.1 BewertungN/A
Veroffentlicht5/13/2026
Zuletzt geandert5/13/2026
Quellenvd
Honeypot-Sichtungen0
Referenzen
https://garmin.com(cve@mitre.org)
https://www8.garmin.com/support/ch.jsp?product=010-02642-00(cve@mitre.org)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.