CVE-2025-64385

Severity CVSS v4.0:
CRITICAL
Type:
CWE-20 Input Validation
Publication date:
31/10/2025
Last modified:
04/11/2025

Description

The equipment initially can be configured using the manufacturer&amp;#39;s application, by Wi-Fi, by the web server or with the manufacturer’s software.<br /> Using the manufacturer&amp;#39;s software, the device can be configured via UDP. Analyzing this communication, it has been observed that any aspect of the initial configuration can be changed by means of the device&amp;#39;s MAC without the need for authentication.