CVE-2025-2764

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 23, 2025
Updated: Apr 29, 2025
CWE ID 798

Summary

CVE-2025-2764 is a critical vulnerability affecting the update.cgi component of CarlinKit CPC200-CCPA devices. The issue involves improper verification of cryptographic signatures, enabling network-adjacent attackers to execute arbitrary code with root privileges. Although authentication is required to exploit this vulnerability, the authentication mechanism can be bypassed. The flaw resides in the handling of update packages, where cryptographic signatures are not adequately verified, allowing malicious code to be executed. This vulnerability, originally identified as ZDI-CAN-24355, can lead to severe consequences if exploited.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share