Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-64385

Gravedad CVSS v4.0:
CRÍTICA
Tipo:
CWE-20 Validación incorrecta de entrada
Fecha de publicación:
31/10/2025
Última modificación:
31/10/2025

Descripción

*** Pendiente de traducción *** The equipment initially can be configured using the manufacturer&amp;#39;s application, by Wi-Fi, by the web server or with the manufacturer’s software.<br /> Using the manufacturer&amp;#39;s software, the device can be configured via UDP. Analyzing this communication, it has been observed that any aspect of the initial configuration can be changed by means of the device&amp;#39;s MAC without the need for authentication.