CVE-2025-63225
BaseFortify
Publication date: 2025-11-18
Last updated on: 2026-02-04
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| eurolab-srl | elts_100_firmware | elts100v1.ubx |
| eurolab | elts100_ubx | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The Eurolab ELTS100_UBX device with firmware version ELTS100v1.UBX has a Broken Access Control vulnerability because it lacks authentication on critical administrative endpoints. This means attackers can remotely access and modify sensitive system and network settings, upload firmware, and perform unauthorized actions without needing to authenticate.
How can this vulnerability impact me? :
This vulnerability allows remote attackers to fully compromise the device, take control of its functionality, and disrupt its operation, potentially leading to loss of device availability, unauthorized changes, and security breaches.