TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2025-63207

CRITICAL
9.8

Beschreibung

The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system compromise.

CVE Details

CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht11/19/2025
Zuletzt geandert1/15/2026
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

rvr:tex1002lcdrvr:tex1002lcd_firmwarervr:tex100lcd\/srvr:tex100lcd\/s_firmwarervr:tex150lcd\/srvr:tex150lcd\/s_firmwarervr:tex2000lightrvr:tex2000light_firmwarervr:tex2500lcdrvr:tex2500lcd_firmwarervr:tex300lcdrvr:tex300lcd_firmwarervr:tex30lcd\/srvr:tex30lcd\/s_firmwarervr:tex3500lcdrvr:tex3500lcd_firmwarervr:tex502lcdrvr:tex502lcd_firmwarervr:tex50lcd\/srvr:tex50lcd\/s_firmwarervr:tex702lcdrvr:tex702lcd_firmware

Schwachen (CWE)

CWE-287

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.