Cleartext Credential Exposure in LITEON Firmware Products
CVE-2025-7357
8.7HIGH
What is CVE-2025-7357?
LITEON IC48A and IC80A firmware prior to specified versions store sensitive FTP server access credentials in cleartext within system logs. This practice poses a significant security risk as unauthorized users gaining access to the logs may extract these plain text credentials, compromising system security. It is essential for users and administrators to update to the latest firmware versions to mitigate this vulnerability and enhance overall system security.
Affected Version(s)
IC48A EV Charger 0 < 01.00.19r
IC80A EV Charger 0 < 01.01.12e