The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system compromise.
References
Configurations
No configuration.
History
20 Nov 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63207_RVR%20Elettronica%20TEX%20Broken%20Access%20ControlĀ - | |
| CWE | CWE-287 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
19 Nov 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-19 18:15
Updated : 2025-11-20 17:15
NVD link : CVE-2025-63207
Mitre link : CVE-2025-63207
CVE.ORG link : CVE-2025-63207
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
