CVE-2025-64385
Severity CVSS v4.0:
CRITICAL
Type:
CWE-20
Input Validation
Publication date:
31/10/2025
Last modified:
04/11/2025
Description
The equipment initially can be configured using the manufacturer&#39;s application, by Wi-Fi, by the web server or with the manufacturer’s software.<br />
Using the manufacturer&#39;s software, the device can be configured via UDP. Analyzing this communication, it has been observed that any aspect of the initial configuration can be changed by means of the device&#39;s MAC without the need for authentication.
Impact
Base Score 4.0
9.20
Severity 4.0
CRITICAL



