CVE-2025-5485
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
12/06/2025
Last modified:
16/06/2025
Description
User names used to access the web management interface are limited to <br />
the device identifier, which is a numerical identifier no more than 10 <br />
digits. A malicious actor can enumerate potential targets by <br />
incrementing or decrementing from known identifiers or through <br />
enumerating random digit sequences.
Impact
Base Score 4.0
8.80
Severity 4.0
HIGH
Base Score 3.x
8.60
Severity 3.x
HIGH



