TROYANOSYVIRUS
Retour aux CVEs

CVE-2025-63207

CRITICAL
9.8

Description

The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system compromise.

Details CVE

Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie11/19/2025
Derniere modification1/15/2026
Sourcenvd
Observations honeypot0

Produits affectes

rvr:tex1002lcdrvr:tex1002lcd_firmwarervr:tex100lcd\/srvr:tex100lcd\/s_firmwarervr:tex150lcd\/srvr:tex150lcd\/s_firmwarervr:tex2000lightrvr:tex2000light_firmwarervr:tex2500lcdrvr:tex2500lcd_firmwarervr:tex300lcdrvr:tex300lcd_firmwarervr:tex30lcd\/srvr:tex30lcd\/s_firmwarervr:tex3500lcdrvr:tex3500lcd_firmwarervr:tex502lcdrvr:tex502lcd_firmwarervr:tex50lcd\/srvr:tex50lcd\/s_firmwarervr:tex702lcdrvr:tex702lcd_firmware

Faiblesses (CWE)

CWE-287

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.