CVE-2025-59409
BaseFortify
Publication date: 2025-10-02
Last updated on: 2025-10-24
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| flocksafety | license_plate_reader_firmware | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-312 | The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 shipping with development Wi-Fi credentials (username: test_flck) stored in cleartext within the production firmware. This means that sensitive Wi-Fi credentials intended only for development or testing are embedded in the device firmware without encryption, potentially allowing unauthorized access.
How can this vulnerability impact me? :
The presence of development Wi-Fi credentials in cleartext in production devices can allow attackers to gain unauthorized access to the device's network or functionality. This could lead to unauthorized data access, manipulation of device operations, or further network compromise.