CVE-2025-27594
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 14, 2025
CWE ID 319
Summary
CVE-2025-27594 refers to a vulnerability in a specific device that utilizes an unencrypted, proprietary communication protocol for configuration data transmission and device authentication. An attacker can exploit this issue by intercepting the authentication hash during transmission, enabling them to perform pass-the-hash attacks and gain unauthorized access to the device. This vulnerability poses a significant risk as sensitive authentication information remains unencrypted, making it vulnerable to interception.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.