Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-53520

Опубликовано: 08 авг. 2025
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks. The TTComp archive format used for the firmware is unencrypted and can be unpacked and altered without detection.

EPSS

Процентиль: 4%
0.00019
Низкий

8.8 High

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 8.8
github
6 месяцев назад

The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks. The TTComp archive format used for the firmware is unencrypted and can be unpacked and altered without detection.

EPSS

Процентиль: 4%
0.00019
Низкий

8.8 High

CVSS3

Дефекты

CWE-494