Brute-force Vulnerability in Electronics Device API from EG4 Electronics
CVE-2025-46414
What is CVE-2025-46414?
A security flaw in the EG4 Electronics API allows for brute-force attacks due to a lack of limits on PIN input attempts for registered devices. An attacker with access to a valid device serial number can exploit this vulnerability to gain unauthorized access to the product. Moreover, the API's feedback mechanism provides detailed confirmation when a correct PIN is entered, making brute-force methods more effective. This issue affects several products and was addressed with a server-side update on April 6, 2025.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EG4 12000XP all versions
EG4 12kPV all versions
EG4 18kPV all versions
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
