Privilege Escalation in ESPEC North America Web Controller by Unprotected GRUB and BIOS
CVE-2025-27846

4.3MEDIUM

Key Information:

Vendor
CVE Published:
14 August 2025

What is CVE-2025-27846?

In ESPEC North America Web Controller versions prior to 3.3.8, a vulnerability exists allowing an attacker with physical access to exploit unprotected GRUB and BIOS configurations. This can lead to unauthorized elevation of privileges, potentially compromising the integrity of the system and exposing sensitive data to malicious actors.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.