« Volver al listado

CVE-2025-63207

Estado: AnalizadaCrítica (9.8)—

The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system compromise.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso remoto sin autenticación a endpoint web (/_Passwd.html) permite cambiar credenciales de todas las cuentas (Admin, Operator, User), rompiendo completamente el control de acceso y resultando en compromiso total del sistema AV:N/PR:N/UI:N.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (11)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-63207",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-63207",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-11-20T16:05:15.241242Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-11-19T18:15:48.793",
  "references": [
    {
      "url": "https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63207_RVR%20Elettronica%20TEX%20Broken%20Access%20Control",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.rvr.it/en/",
      "tags": [
        "Product"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63207_RVR%20Elettronica%20TEX%20Broken%20Access%20Control",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system compromise."
    }
  ],
  "lastModified": "2026-06-17T09:52:56.140",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rvr:tex30lcd\\/s_firmware:texl-000400:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2DDF5675-06D9-4A01-9490-A9D83F1BA254"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rvr:tex30lcd\\/s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "53A05670-711A-4D6F-89BB-8849DE507C76"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rvr:tex50lcd\\/s_firmware:texl-000400:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CB3442C-B734-4A95-A25D-CF99E07E588B"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rvr:tex50lcd\\/s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "ACF54374-2D10-44DC-B481-F2449F552BB3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rvr:tex100lcd\\/s_firmware:texl-000400:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B85488D3-A8E1-4175-83F9-CAE585C4DAB6"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rvr:tex100lcd\\/s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "64F185C9-A27D-4AFC-A54A-1C44802A5A66"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rvr:tex150lcd\\/s_firmware:texl-000400:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A48CEA2-0AD8-4B71-A97D-08E7D08ED47B"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rvr:tex150lcd\\/s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E75BDA11-64D1-4B95-91E6-91AFB96F4645"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rvr:tex300lcd_firmware:texl-000400:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C03FFF4B-9FD0-4B0C-97B3-A3242FEA5997"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rvr:tex300lcd:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8DA92AF5-0B36-4302-8883-8BA850A7F14F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rvr:tex502lcd_firmware:texl-000400:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0355114A-0AC4-48F9-B8C8-024F10DF26CD"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rvr:tex502lcd:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CA1BF06A-C075-4800-8148-98B7893EE420"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rvr:tex702lcd_firmware:texl-000400:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FF2E4711-65E2-4E5A-8289-1C363C1604F9"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rvr:tex702lcd:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3BC81BA3-7998-40BB-BE4C-3B356B6E24AF"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rvr:tex3500lcd_firmware:texl-000400:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62922A5A-4B27-46B6-8BAE-8C2C2EE6874A"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rvr:tex3500lcd:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FE5ADADE-4D33-40D0-ACAC-B67E444E82E2"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rvr:tex1002lcd_firmware:texl-000400:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D62504CB-796F-4B47-BB9C-39C349C28A9A"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rvr:tex1002lcd:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A99A80B0-50CD-4115-A161-F4AEFF2E5931"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rvr:tex2000light_firmware:texl-000400:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6B77727-86B7-4590-95CA-928657E82326"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rvr:tex2000light:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "636F6C0B-2756-47D1-9699-3F8A51C698A3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rvr:tex2500lcd_firmware:texl-000400:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34614E9B-4BC0-45BE-945D-3752697AC709"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rvr:tex2500lcd:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4777DA5E-B154-4FAD-920C-95635C8EA6B9"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}