CVE-2025-10127

Severity CVSS v4.0:
HIGH
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
11/09/2025
Last modified:
18/09/2025

Description

Daikin Europe N.V<br /> <br /> Security Gateway is vulnerable to an authorization bypass through<br /> a user-controlled key vulnerability that could allow an attacker to <br /> bypass authentication. An unauthorized attacker could access the system <br /> without prior credentials.