Improper Authentication in Multilaser Sirius RE016 by Multilaser
CVE-2025-5437
What is CVE-2025-5437?
A security vulnerability has been identified in the Multilaser Sirius RE016 MLT1.0, specifically affecting the Password Change Handler located in the file /cgi-bin/cstecgi.cgi. This flaw allows for improper authentication, enabling potential unauthorized access to the system. Attackers can exploit this vulnerability remotely, increasing the risk of exploitation. Despite attempts to notify the vendor, there has been no response regarding this significant security concern. Users and admins of the affected product are advised to take immediate action to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Sirius RE016 MLT1.0
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
