CVE-2025-13510
Severity CVSS v4.0:
CRITICAL
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
02/12/2025
Last modified:
02/12/2025
Description
The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authentication, allowing unauthenticated users to access and modify critical device settings.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL



