Predictable Password Vulnerability in E3 Site Supervisor Firmware by Armis
CVE-2025-6519

9.3CRITICAL

Key Information:

Vendor
CVE Published:
2 September 2025

What is CVE-2025-6519?

The E3 Site Supervisor, running firmware versions earlier than 2.31F01, is vulnerable due to the presence of a default admin user named 'ONEDAY' that comes with a password generated daily based on a predictable algorithm. This predictability allows an attacker to easily deduce the admin password, compromising the security of the device and potentially leading to unauthorized access. Notably, the ONEDAY user account cannot be deleted or modified by any user, exacerbating the vulnerability and leaving systems exposed to attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

E3 Supervisory Control 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Armis Labs
.