« Volver al listado

CVE-2025-5832

Estado: AnalizadaMedia (6.8)—

Pioneer DMH-WT7600NEX Software Update Signing Insufficient Verification of Data Authenticity Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the software update verification process. The issue results from the lack of validating all the data in the software update. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-26079.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-5832",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-5832",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-06-25T18:26:11.005588Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "zdi-disclosures@trendmicro.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 6.8,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.9
      }
    ]
  },
  "affected": [
    {
      "source": "zdi-disclosures@trendmicro.com",
      "affectedData": [
        {
          "vendor": "Pioneer",
          "product": "DMH-WT7600NEX",
          "versions": [
            {
              "status": "affected",
              "version": "3.05"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2025-06-25T18:15:24.077",
  "references": [
    {
      "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-352/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "zdi-disclosures@trendmicro.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "zdi-disclosures@trendmicro.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-345"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Pioneer DMH-WT7600NEX Software Update Signing Insufficient Verification of Data Authenticity Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the software update verification process. The issue results from the lack of validating all the data in the software update. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-26079."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de verificación insuficiente de la autenticidad de los datos en la firma de actualizaciones de software del Pioneer DMH-WT7600NEX. Esta vulnerabilidad permite a atacantes con presencia física ejecutar código arbitrario en las instalaciones afectadas de los dispositivos Pioneer DMH-WT7600NEX. No se requiere autenticación para explotar esta vulnerabilidad. La falla específica se encuentra en el proceso de verificación de actualizaciones de software. El problema se debe a la falta de validación de todos los datos en la actualización de software. Un atacante puede aprovechar esta vulnerabilidad para ejecutar código en el contexto del dispositivo. Era ZDI-CAN-26079."
    }
  ],
  "lastModified": "2026-06-17T09:48:50.123",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:pioneer:dmh-wt7600nex_firmware:3.05:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE9170F1-CDF6-49D5-9501-A3DA09D419CB"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:pioneer:dmh-wt7600nex:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E9082E28-D451-488C-A621-4A174B887EB3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "zdi-disclosures@trendmicro.com"
}