CVE-2020-25746
Status: ModifiedMedium (4.6)—
QED ResourceXpress Qubi3 devices before 1.40.9 could allow a local attacker (with physical access to the device) to obtain sensitive information via the debug interface (keystrokes over a USB cable), aka wireless password visibility.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Base score: 4.6
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.31%
- Percentile among all scored CVEs: 22
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-200
References
- https://resourcexpress.atlassian.net/wiki/spaces/RSG/pages/878641153/v1.40.9
- https://www.resourcexpress.com/meeting-room-booking-systems/hardware/qubi3/
- https://resourcexpress.atlassian.net/wiki/spaces/RSG/pages/878641153/v1.40.9
- https://www.resourcexpress.com/meeting-room-booking-systems/hardware/qubi3/
Raw JSON (NVD)
Show
{
"id": "CVE-2020-25746",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.6,
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2020-11-17T14:15:11.353",
"references": [
{
"url": "https://resourcexpress.atlassian.net/wiki/spaces/RSG/pages/878641153/v1.40.9",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.resourcexpress.com/meeting-room-booking-systems/hardware/qubi3/",
"tags": [
"Product",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://resourcexpress.atlassian.net/wiki/spaces/RSG/pages/878641153/v1.40.9",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.resourcexpress.com/meeting-room-booking-systems/hardware/qubi3/",
"tags": [
"Product",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "QED ResourceXpress Qubi3 devices before 1.40.9 could allow a local attacker (with physical access to the device) to obtain sensitive information via the debug interface (keystrokes over a USB cable), aka wireless password visibility."
},
{
"lang": "es",
"value": "Unos dispositivos QED ResourceXpress Qubi3 versiones anteriores a 1.40.9, podían permitir a un atacante local (con acceso físico al dispositivo) conseguir información confidencial por medio de la interfaz de depuración (pulsaciones de teclas por medio de un cable USB), también se conoce como visibilidad de contraseña inalámbrica"
}
],
"lastModified": "2026-06-17T03:07:13.837",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:resourcexpress:qubi3_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B96BFA1D-A37D-42EF-A335-3508B1F2EFB6",
"versionEndExcluding": "1.40.9"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:resourcexpress:qubi3:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "401A7A22-1DEB-495D-B753-641E6B7FF339"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}