CVE-2025-46414
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
08/08/2025
Last modified:
08/08/2025
Description
The affected product does not limit the number of attempts for inputting<br />
the correct PIN for a registered product, which may allow an attacker <br />
to gain unauthorized access using brute-force methods if they possess a <br />
valid device serial number. The API provides clear feedback when the <br />
correct PIN is entered. This vulnerability was patched in a server-side <br />
update on April 6, 2025.
Impact
Base Score 4.0
9.20
Severity 4.0
CRITICAL
Base Score 3.x
8.10
Severity 3.x
HIGH



