Undocumented Telnet Service Exposes Blackmagic ATEM Mini Pro to Remote Control Risks
CVE-2025-57440
7.5HIGH
What is CVE-2025-57440?
The Blackmagic ATEM Mini Pro 2.7 features an undocumented Telnet service on TCP port 9993 that allows unauthenticated access to control various device functions. This protocol, named the "ATEM Ethernet Protocol 1.0", enables attackers on the same network, or those with access to the open port, to issue arbitrary commands without authentication. Exploiting this vulnerability could allow an attacker to manipulate streaming settings, erase storage devices, or even reboot the system, leading to a complete compromise of streaming operations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
