Cleartext Credential Exposure in LITEON Firmware Products
CVE-2025-7357

8.7HIGH

Key Information:

Vendor

Liteon

Vendor
CVE Published:
16 July 2025

What is CVE-2025-7357?

LITEON IC48A and IC80A firmware prior to specified versions store sensitive FTP server access credentials in cleartext within system logs. This practice poses a significant security risk as unauthorized users gaining access to the logs may extract these plain text credentials, compromising system security. It is essential for users and administrators to update to the latest firmware versions to mitigate this vulnerability and enhance overall system security.

Affected Version(s)

IC48A EV Charger 0 < 01.00.19r

IC80A EV Charger 0 < 01.01.12e

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Murat Sagdullaev of Electrada
.
CVE-2025-7357 : Cleartext Credential Exposure in LITEON Firmware Products