Authentication Bypass Vulnerability in IoT Devices by Vendor XYZ
CVE-2025-27803

6.5MEDIUM

Key Information:

Vendor
CVE Published:
21 May 2025

What is CVE-2025-27803?

The lack of authentication for the web interface and MQTT server in certain IoT devices from Vendor XYZ exposes them to severe risks. An attacker with network access can easily gain administrative control, enabling them to execute arbitrary actions, reconfigure device settings, or retrieve sensitive information. This vulnerability emphasizes the need for robust authentication mechanisms to safeguard user data and device integrity.

Affected Version(s)

cPH2 / cPP2 charging stations <=2.2.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stefan Viehböck | SEC Consult Vulnerability Lab
.