Improper Authentication in Novakon P Series Devices
CVE-2025-9965

9.3CRITICAL

Key Information:

Vendor

Novakon

Status
Vendor
CVE Published:
23 September 2025

What is CVE-2025-9965?

The Novakon P series devices have a vulnerability that enables unauthenticated attackers to access the system, allowing them to upload and download applications directly to and from the device. This flaw compromises the integrity of the device's security, as it exposes critical functionalities to unauthorized users, potentially leading to data breaches and unauthorized system modifications.

Affected Version(s)

P series Linux P – V2001.A.c518o2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

S. Dietz (CyberDanube)
.
CVE-2025-9965 : Improper Authentication in Novakon P Series Devices