CVE-2025-5484
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
12/06/2025
Last modified:
16/06/2025
Description
A username and password are required to authenticate to the central <br />
SinoTrack device management interface. The username for all devices is <br />
an identifier printed on the receiver. The default password is <br />
well-known and common to all devices. Modification of the default <br />
password is not enforced during device setup. A malicious actor can <br />
retrieve device identifiers with either physical access or by capturing <br />
identifiers from pictures of the devices posted on publicly accessible <br />
websites such as eBay.
Impact
Base Score 4.0
7.60
Severity 4.0
HIGH
Base Score 3.x
8.30
Severity 3.x
HIGH



