CVE-2025-15575 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

The firmware update functionality does not verify the authenticity of the supplied firmware update files. This allows attackers to flash malicious firmware upda…
Medium CVSS: 5.3

CVE-2025-15575

The firmware update functionality does not verify the authenticity of the supplied firmware update files. This allows attackers to flash malicious firmware update files on the device. Initial analysis of the firmware update functionality does not show any cryptographic checks (e.g. digital signature checks) on the supplied firmware update files. Furthermore, ESP32 security features such as secure boot are not used.
Vendor
-
Product
-
CWE
CWE-494
Yayın Tarihi
2026-02-12 11:15:49
Güncelleme
2026-02-12 16:16:03
Source Identifier
551230f0-3615-47bd-b7cc-93e92e730bbf
KEV Date Added
-

Kategoriler

Referanslar