CVE-2025-5833
Pioneer DMH-WT7600NEX Root Filesystem Insufficient Verification of Data Authenticity Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the configuration of the operating system. The issue results from the lack of properly configured protection for the root file system. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-26077.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.26%
- Percentil entre todas las CVEs puntuadas: 16
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-345
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-5833",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-5833",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-06-25T18:23:25.395564Z"
}
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "zdi-disclosures@trendmicro.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 4.6,
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 0.9
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "zdi-disclosures@trendmicro.com",
"affectedData": [
{
"vendor": "Pioneer",
"product": "DMH-WT7600NEX",
"versions": [
{
"status": "affected",
"version": "3.05"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2025-06-25T18:15:24.203",
"references": [
{
"url": "https://www.zerodayinitiative.com/advisories/ZDI-25-350/",
"tags": [
"Third Party Advisory"
],
"source": "zdi-disclosures@trendmicro.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "zdi-disclosures@trendmicro.com",
"description": [
{
"lang": "en",
"value": "CWE-345"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Pioneer DMH-WT7600NEX Root Filesystem Insufficient Verification of Data Authenticity Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the configuration of the operating system. The issue results from the lack of properly configured protection for the root file system. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-26077."
},
{
"lang": "es",
"value": "Vulnerabilidad de verificación insuficiente de la autenticidad de datos en el sistema de archivos raíz del Pioneer DMH-WT7600NEX. Esta vulnerabilidad permite a atacantes presentes físicamente eludir la autenticación en las instalaciones afectadas de los dispositivos Pioneer DMH-WT7600NEX. No se requiere autenticación para explotar esta vulnerabilidad. La falla específica se encuentra en la configuración del sistema operativo. El problema se debe a la falta de una protección configurada correctamente para el sistema de archivos raíz. Un atacante puede aprovechar esta vulnerabilidad para eludir la autenticación en el sistema. Anteriormente, se denominaba ZDI-CAN-26077."
}
],
"lastModified": "2026-06-17T09:48:50.237",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:pioneer:dmh-wt7600nex_firmware:3.05:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE9170F1-CDF6-49D5-9501-A3DA09D419CB"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:pioneer:dmh-wt7600nex:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E9082E28-D451-488C-A621-4A174B887EB3"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "zdi-disclosures@trendmicro.com"
}