Hard-coded cryptographic keys in EZCast Pro II Dongle
CVE-2025-13954

9.3CRITICAL

Key Information:

Vendor

Ezcast

Vendor
CVE Published:
10 December 2025

What is CVE-2025-13954?

Hard-coded cryptographic keys in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to the admin UI

Affected Version(s)

EZCast Pro II 1.17478.146

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Swiss National Test Institute for Cybersecurity NTC
Swiss National Cybersecurity Centre
.
CVE-2025-13954 : Authorization Bypass in EZCast Pro II Admin UI