CVE-2025-5095
Severity CVSS v4.0:
CRITICAL
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
08/08/2025
Last modified:
08/08/2025
Description
Burk Technology ARC Solo&#39;s password change mechanism can be utilized without proper <br />
authentication procedures, allowing an attacker to take over the device.<br />
A password change request can be sent directly to the device&#39;s HTTP <br />
endpoint without providing valid credentials. The system does not <br />
enforce proper authentication or session validation, allowing the <br />
password change to proceed without verifying the request&#39;s legitimacy.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
9.80
Severity 3.x
CRITICAL



