Unauthorized Access Vulnerability in Novakon P Series
CVE-2025-9964

8.6HIGH

Key Information:

Vendor

Novakon

Status
Vendor
CVE Published:
23 September 2025

What is CVE-2025-9964?

The Novakon P series suffers from a significant security issue where the root user account is not secured with a password. This oversight permits physical attackers easy access to the device console, potentially compromising the system's integrity. This vulnerability highlights the crucial importance of implementing robust authentication measures in industrial control systems to mitigate risks associated with unauthorized physical access.

Affected Version(s)

P series Linux P – V2001.A.c518o2

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

S. Dietz (CyberDanube)
.
CVE-2025-9964 : Unauthorized Access Vulnerability in Novakon P Series