CVE ID | CVE-2025-2765 |
CVSS SCORE | 7.6, AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |
AFFECTED VENDORS |
CarlinKit |
AFFECTED PRODUCTS |
CPC200-CCPA |
VULNERABILITY DETAILS |
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of CarlinKit CPC200-CCPA devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the wireless hotspot. The issue results from the use of hard-coded credentials. An attacker can leverage this vulnerability to bypass authentication on the system. |
ADDITIONAL DETAILS |
06/05/24 – ZDI contacted the vendor’s support team via email |
DISCLOSURE TIMELINE |
|
CREDIT | Aaron Luo and Spencer Hsieh of VicOne |