TROYANOSYVIRUS
Back to CVEs

CVE-2025-3927

CRITICAL
9.8

Description

Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with the target IP address to connect and compromise the device, potentially pivoting to connected network or hardware devices.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published5/2/2025
Last Modified6/17/2025
Sourcenvd
Honeypot Sightings0

Affected Products

digigram:pyko-out

Weaknesses (CWE)

CWE-862

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.