The ELCA Star Transmitter Remote Control firmware 1
Description
The ELCA Star Transmitter Remote Control firmware 1
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
8 vulnerabilities from Control
← Back to all CVEsThe ELCA Star Transmitter Remote Control firmware 1
The ELCA Star Transmitter Remote Control firmware 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10
Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10
---METADATA---
VENDOR: HCL Software
PRODUCT: BigFix Remote Control
AFFECTED_VERSIONS: <=10.1.0.0248
CONFIDENCE: high
MISSING: none
SOURCES_JSON: [{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0122906","name":"VDB-299060 | PyTorch Quantized Sigmoid Module nnq_Sigmoid initialization","tags":["x_refsource_CONFIRM"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T19:15:08.282Z
---END_METADATA---
Description Summary:
HCL BigFix Remote Control Server WebUI contains an improper access restriction vulnerability that allows non-admin users to view unauthorized information.
Executive Summary:
A high-severity authentication bypass vulnerability in HCL BigFix Remote Control allows unauthorized users with limited access to view sensitive information within the WebUI.
Vulnerability Details
CVE-ID: CVE-2025-31965
Affected Software: HCL Software BigFix Remote Control
Affected Versions: <=10.1.0.0248
Vulnerability: This vulnerability is classified as an authentication bypass (CWE-305), where improper access restrictions in the WebUI permit authenticated users with low privileges to access unauthorized information on specific web pages.
Business Impact
The vulnerability carries a CVSS score of 8.2, reflecting a significant risk to data confidentiality and integrity. Unauthorized information disclosure within a remote control management platform can lead to the exposure of sensitive infrastructure details, potentially facilitating further attacks against the managed environment.
Remediation Plan
Immediate Action: Update HCL BigFix Remote Control to the version specified in the vendor advisory (KB0122906) to remediate the access control flaw.
Proactive Monitoring: Review web server access logs for anomalous request patterns or unauthorized attempts by low-privileged users to access sensitive administrative endpoints.
Compensating Controls: Implement strict network segmentation and ensure that access to the BigFix Remote Control WebUI is restricted to authorized administrative segments via a VPN or firewall rules.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 30, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. While the risk of active exploitation is currently low, the capability for lower-privileged users to bypass intended access controls represents a notable security posture deficiency.
Analyst Recommendation
Given the high CVSS score and the nature of the vulnerability within a management interface, administrators should prioritize applying the vendor-supplied patch. Organizations should verify their current version of BigFix Remote Control against the affected range and schedule maintenance windows to ensure the environment is secured against potential unauthorized access.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Hestia Control Panel 1
Hestia Control Panel 1
---METADATA---
VENDOR: Hestia
PRODUCT: Control Panel
AFFECTED_VERSIONS: 1.3.2 and below
CONFIDENCE: high
MISSING: none
CREDITS: Numan Türle (finder)
SOURCES_JSON: [{"url":"https://www.exploit-db.com/exploits/49667","name":"ExploitDB-49667","tags":["exploit"]},{"url":"https://hestiacp.com/","name":"Hestia Control Panel Official Homepage","tags":["product"]},{"url":"https://github.com/hestiacp/hestiacp","name":"Hestia Control Panel GitHub Repository","tags":["product"]},{"url":"https://www.vulncheck.com/advisories/hestia-control-panel-arbitrary-file-write","name":"VulnCheck Advisory: Hestia Control Panel 1.3.2 - Arbitrary File Write","tags":["third-party-advisory"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T14:11:37.114Z
---END_METADATA---
Description Summary:
Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability in the API index.php endpoint, allowing authenticated attackers to write files to arbitrary locations.
Executive Summary:
An arbitrary file write vulnerability in Hestia Control Panel 1.3.2 allows authenticated attackers to execute unauthorized file operations, posing a severe risk of system compromise.
Vulnerability Details
CVE-ID: CVE-2021-47871
Affected Software: Hestia Control Panel
Affected Versions: 1.3.2 and below
Vulnerability: The application is susceptible to an arbitrary file write vulnerability via the API index.php endpoint. By leveraging the v-make-tmp-file command, an authenticated attacker can write files to sensitive locations, such as adding unauthorized SSH keys to the server.
Business Impact
Successful exploitation of this vulnerability allows an authenticated attacker to gain full control over the affected server. By writing arbitrary content to critical file paths, such as SSH authorized_keys, an attacker can establish persistent backdoor access, resulting in complete system compromise and potential data exfiltration. Given the CVSS score of 8.8, this vulnerability represents a high-severity threat that requires immediate attention to prevent unauthorized administrative access.
Remediation Plan
Immediate Action: Upgrade Hestia Control Panel to version 1.3.3 or later immediately to incorporate the necessary security patches.
Proactive Monitoring: Review system logs for suspicious API requests to index.php, particularly those invoking the v-make-tmp-file command with unusual file paths.
Compensating Controls: Restrict access to the API endpoint to trusted IP addresses using a Web Application Firewall or network-level access control lists to limit the exposure of the management interface.
Exploitation Status
Public Exploit Available: Yes, a public exploit exists as documented in the Exploit Database (EDB-ID: 49667).
Analyst Notes: As of January 23, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly exploitable due to the direct nature of the API command, which requires only valid authentication to execute.
Analyst Recommendation
This vulnerability presents a significant risk to the integrity and confidentiality of the Hestia Control Panel environment. Administrators should prioritize updating the software to version 1.3.3 or higher to close the file write vector. Failure to patch may allow attackers to escalate privileges or establish persistence, leading to a complete system takeover.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
FaceSentry Access Control System 6
FaceSentry Access Control System 6
---METADATA---
VENDOR: iWT Ltd.
PRODUCT: FaceSentry Access Control System
AFFECTED_VERSIONS: 6.4.8 build 264, 5.7.2 build 568, 5.7.0 build 539
CONFIDENCE: high
MISSING: patch
CREDITS: LiquidWorm as Gjoko Krstic of Zero Science Lab (finder)
SOURCES_JSON: [{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5529.php","name":"Zero Science Lab Vulnerability Advisory","tags":["third-party-advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/163190","name":"IBM X-Force Exchange Vulnerability Entry","tags":["vdb-entry"]},{"url":"https://packetstormsecurity.com/files/153501","name":"Packet Storm Security Exploit Entry","tags":["exploit"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T14:11:36.254Z
---END_METADATA---
Description Summary:
FaceSentry Access Control System stores sensitive credentials in cleartext within a local SQLite database, allowing unauthorized access to login information.
Executive Summary:
A cleartext storage vulnerability in iWT Ltd. FaceSentry Access Control System allows attackers to compromise sensitive credentials stored in the device database.
Vulnerability Details
CVE-ID: CVE-2019-25279
Affected Software: iWT Ltd. FaceSentry Access Control System
Affected Versions: 6.4.8 build 264, 5.7.2 build 568, 5.7.0 build 539
Vulnerability: This vulnerability involves the insecure, cleartext storage of sensitive information within the /faceGuard/database/FaceSentryWeb.sqlite file. An attacker with local access to the system can read unencrypted credentials directly from the database without requiring authentication.
Business Impact
The compromise of administrative credentials poses a significant security risk, as it allows unauthorized actors to gain full control over physical access management systems. This exposure can lead to unauthorized facility entry, manipulation of security logs, and a total loss of confidentiality regarding user authentication data. While the CVSS score is 8.2, the potential for physical security breaches makes this a high-priority risk.
Remediation Plan
Immediate Action: Contact iWT Ltd. support immediately to determine if a patch or firmware update is available for your specific build, as no public patch is currently confirmed.
Proactive Monitoring: Review system access logs for any unauthorized attempts to access or transfer the SQLite database files located in the /faceGuard/database/ directory.
Compensating Controls: Restrict local access to the affected hardware components and ensure that the device file system is protected by physical security measures to prevent unauthorized extraction of the database.
Exploitation Status
Public Exploit Available: Yes, a proof-of-concept is documented in the technical write-up published by Packet Storm Security.
Analyst Notes: As of January 9, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is inherently easy to exploit due to the lack of encryption on sensitive data files.
Analyst Recommendation
Given the sensitivity of access control systems, this vulnerability should be treated with urgency. Administrators must restrict physical and logical access to the device immediately while awaiting formal guidance or remediation from the vendor. Failure to secure these credentials could facilitate unauthorized physical access to protected environments.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
FaceSentry Access Control System 6
FaceSentry Access Control System 6
---METADATA---
VENDOR: iWT Ltd.
PRODUCT: FaceSentry Access Control System
AFFECTED_VERSIONS: 6.4.8 build 264, 5.7.2 build 568, 5.7.0 build 539
CONFIDENCE: high
MISSING: none
CREDITS: LiquidWorm as Gjoko Krstic of Zero Science Lab (finder)
SOURCES_JSON: [{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5528.php","name":"Zero Science Lab Vulnerability Advisory","tags":["third-party-advisory"]},{"url":"https://packetstormsecurity.com/files/153498","name":"Packet Storm Security Exploit Entry","tags":["exploit"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/163192","name":"IBM X-Force Vulnerability Exchange Entry","tags":["vdb-entry"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T14:11:36.254Z
---END_METADATA---
Description Summary:
FaceSentry Access Control System transmits authentication credentials in cleartext, allowing remote attackers to intercept sensitive HTTP cookie information via man-in-the-middle attacks.
Executive Summary:
A cleartext transmission vulnerability in the iWT Ltd. FaceSentry Access Control System allows remote attackers to intercept authentication credentials, posing a significant risk of unauthorized access.
Vulnerability Details
CVE-ID: CVE-2019-25278
Affected Software: iWT Ltd. FaceSentry Access Control System
Affected Versions: 6.4.8 build 264, 5.7.2 build 568, 5.7.0 build 539
Vulnerability: This vulnerability involves the transmission of sensitive authentication data over unencrypted channels. An unauthenticated attacker positioned on the network path can perform man-in-the-middle attacks to capture HTTP cookie information, which can subsequently be used to hijack user sessions.
Business Impact
The ability for an attacker to capture authentication cookies directly leads to full account takeover of affected users, including administrative accounts if targeted. Given the CVSS score of 7.5, this high-severity flaw threatens the confidentiality and integrity of the entire access control system, potentially allowing unauthorized physical or digital access to protected facilities or networks.
Remediation Plan
Immediate Action: Update the FaceSentry Access Control System to a secure version that mandates encrypted communication (HTTPS) for all traffic. If an update is not immediately feasible, restrict network access to the management interface to trusted segments only.
Proactive Monitoring: Monitor network traffic for unusual patterns, such as the unauthorized interception of HTTP traffic or unexpected session initiation from unknown IP addresses. Review system logs for signs of account anomalies or concurrent session logins.
Compensating Controls: Deploy a Web Application Firewall (WAF) or a VPN to enforce encryption for all traffic traversing the network. Ensure that administrative access is restricted to encrypted channels and enforce multi-factor authentication where supported.
Exploitation Status
Public Exploit Available: Yes, a technical write-up detailing the attack methodology is available via Packet Storm Security.
Analyst Notes: As of February 18, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The flaw is inherently exploitable because it relies on standard network interception techniques that do not require specialized authentication.
Analyst Recommendation
This vulnerability presents a high risk to organizational security due to the potential for session hijacking. Administrators must prioritize updating the affected software to a version that enforces transport-layer security. In the interim, ensure all management interfaces are isolated from public-facing networks to prevent potential attackers from positioning themselves to intercept sensitive authentication data.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
FaceSentry Access Control System 6
FaceSentry Access Control System 6
---METADATA---
VENDOR: iWT Ltd.
PRODUCT: FaceSentry Access Control System
AFFECTED_VERSIONS: 6.4.8 build 264, 5.7.2 build 568, 5.7.0 build 539
CONFIDENCE: high
MISSING: none
CREDITS: LiquidWorm as Gjoko Krstic of Zero Science Lab (finder)
SOURCES_JSON: [{"url":"https://www.exploit-db.com/exploits/47067","name":"ExploitDB-47067","tags":["exploit"]},{"url":"http://www.iwt.com.hk","name":"Vendor Product Homepage","tags":["product"]},{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5526.php","name":"Zero Science Lab Disclosure (ZSL-2019-5526)","tags":["third-party-advisory"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T14:11:39.874Z
---END_METADATA---
Description Summary:
FaceSentry Access Control System contains hard-coded SSH credentials and an insecure sudoers configuration, allowing unauthenticated attackers to gain root-level access to the appliance.
Executive Summary:
A critical vulnerability in the iWT Ltd. FaceSentry Access Control System permits unauthenticated remote attackers to achieve full root system compromise via hard-coded credentials.
Vulnerability Details
CVE-ID: CVE-2019-25241
Affected Software: iWT Ltd. FaceSentry Access Control System
Affected Versions: 6.4.8 build 264, 5.7.2 build 568, 5.7.0 build 539
Vulnerability: The device ships with hard-coded SSH credentials (wwwuser:123456) on port 23445, combined with an insecure sudoers configuration that permits the user to execute all commands as root without a password. This allows an unauthenticated attacker to bypass all security controls and gain full administrative control over the hardware.
Business Impact
Successful exploitation of this vulnerability grants an attacker complete control over the physical access control appliance, which could lead to unauthorized entry, manipulation of security logs, or the disabling of facility security systems. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to the physical security and data integrity of the environment where the system is deployed.
Remediation Plan
Immediate Action: Update the device firmware to a version that removes the hard-coded credentials and restricts sudoers privileges. If an update is not immediately available, disable SSH access on the device or restrict access to the management port via a strictly controlled network segment.
Proactive Monitoring: Monitor network traffic for unauthorized connection attempts to port 23445 and review system logs for suspicious sudo command execution or unexpected user activity.
Compensating Controls: Implement network-level access control lists (ACLs) to ensure that only authorized administrative workstations can communicate with the device on the SSH management port.
Exploitation Status
Public Exploit Available: Yes, a functional exploit script exists on ExploitDB (EDB-ID: 47067).
Analyst Notes: As of December 26, 2025, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly exploitable due to the trivial nature of the hard-coded credentials and the publicly available exploit code.
Analyst Recommendation
This vulnerability represents a severe risk to physical security infrastructure due to the ease with which an attacker can obtain root access. Administrators must prioritize updating affected hardware immediately or isolating the devices from the network to prevent unauthorized access. Failure to remediate this issue could allow an attacker to bypass physical entry controls entirely.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
SOCA Access Control System 180612 contains multiple insecure direct object reference vulnerabilities that allow attackers to access sensitive user cre...
SOCA Access Control System 180612 contains multiple insecure direct object reference vulnerabilities that allow attackers to access sensitive user credentials
---METADATA---
VENDOR: SOCA Technology Co., Ltd
PRODUCT: Access Control System
AFFECTED_VERSIONS: 180612, 170000, 141007
CONFIDENCE: high
MISSING: patch
CREDITS: LiquidWorm as Gjoko Krstic of Zero Science Lab (finder)
SOURCES_JSON: [{"url":"https://www.exploit-db.com/exploits/46832","name":"ExploitDB-46832","tags":["exploit"]},{"url":"http://www.socatech.com","name":"SOCA Technology Product Homepage","tags":["product"]},{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5517.php","name":"Zero Science Lab Disclosure (ZSL-2019-5517)","tags":["third-party-advisory"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T14:11:39.878Z
---END_METADATA---
Description Summary:
SOCA Access Control System contains multiple insecure direct object reference vulnerabilities, allowing attackers to retrieve sensitive user credentials and PINs via unprotected endpoints.
Executive Summary:
The SOCA Access Control System is vulnerable to multiple insecure direct object reference flaws that allow unauthorized access to sensitive user credentials, posing a significant risk to physical and digital security.
Vulnerability Details
CVE-ID: CVE-2018-25129
Affected Software: SOCA Technology Co., Ltd Access Control System
Affected Versions: 180612, 170000, 141007
Vulnerability: The system suffers from insecure direct object reference (IDOR) vulnerabilities in the Get_Permissions_From_DB.php and Ac10_ReadSortCard endpoints. These flaws allow both authenticated and unauthenticated attackers to bypass authorization controls and extract sensitive information, including user password hashes and access PINs.
Business Impact
A successful exploit allows an attacker to obtain administrative or user credentials, which could lead to unauthorized physical access to facilities managed by the access control system. Given the CVSS score of 7.5, the vulnerability is classified as High severity, as it facilitates unauthorized data disclosure that directly compromises the integrity and security of the access control environment.
Remediation Plan
Immediate Action: As no official patch is currently available, restrict access to the web management interface by placing it behind a VPN or firewall, ensuring it is not exposed to the public internet.
Proactive Monitoring: Review web server and application access logs for suspicious requests directed at the Get_Permissions_From_DB.php and Ac10_ReadSortCard endpoints, particularly those originating from unauthorized IP addresses.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block or flag requests containing parameters that attempt to access these specific vulnerable PHP and CGI endpoints.
Exploitation Status
Public Exploit Available: Yes, a functional proof-of-concept exploit is available via ExploitDB (EDB-ID: 46832).
Analyst Notes: As of December 26, 2025, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The availability of a public exploit simplifies the attack process, making the immediate implementation of network-level access restrictions critical.
Analyst Recommendation
Due to the sensitive nature of the exposed credentials and the presence of a public exploit, this vulnerability must be treated with high urgency. Organizations utilizing the affected SOCA Access Control System versions should immediately isolate the management interface from untrusted networks and evaluate alternative security measures until a vendor-supplied update is released.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
SOCA Access Control System 180612 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through unvalida...
SOCA Access Control System 180612 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through unvalidated POST parameters
---METADATA---
VENDOR: SOCA Technology Co., Ltd
PRODUCT: SOCA Access Control System
AFFECTED_VERSIONS: 180612, 170000, 141007
CONFIDENCE: high
MISSING: patch
CREDITS: LiquidWorm as Gjoko Krstic of Zero Science Lab (finder)
SOURCES_JSON: [{"url":"https://www.exploit-db.com/exploits/46833","name":"ExploitDB-46833","tags":["exploit"]},{"url":"http://www.socatech.com","name":"SOCA Technology Product Homepage","tags":["product"]},{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5519.php","name":"Zero Science Lab Disclosure (ZSL-2019-5519)","tags":["third-party-advisory"]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T19:15:01.082Z
---END_METADATA---
Description Summary:
SOCA Access Control System contains multiple SQL injection vulnerabilities in Login.php and Card_Edit_GetJson.php, allowing unauthenticated attackers to bypass authentication and gain system access.
Executive Summary:
The SOCA Access Control System is vulnerable to unauthenticated SQL injection, which can lead to complete unauthorized administrative access and potential physical security bypass.
Vulnerability Details
CVE-ID: CVE-2018-25128
Affected Software: SOCA Technology Co., Ltd SOCA Access Control System
Affected Versions: 180612, 170000, 141007
Vulnerability: This vulnerability is a SQL injection flaw (CWE-89) where unvalidated POST parameters in the Login.php and Card_Edit_GetJson.php files allow an unauthenticated attacker to execute arbitrary SQL commands. This enables authentication bypass, the retrieval of database contents including password hashes, and the escalation of privileges to an administrative level.
Business Impact
The exploitation of this vulnerability poses a severe risk to organizational security, as it allows attackers to gain full administrative control over the access control system. Because this system manages physical entry points, unauthorized access could lead to the compromise of sensitive facilities, potential theft, and significant physical security breaches. With a CVSS score of 8.2, this vulnerability is classified as High severity and requires immediate attention to prevent unauthorized system manipulation.
Remediation Plan
Immediate Action: There is no official patch available from the vendor. Organizations should immediately restrict network access to the SOCA Access Control System interface, ensuring it is not exposed to the public internet or untrusted network segments.
Proactive Monitoring: Review web server logs for suspicious POST requests containing SQL syntax, particularly those directed at Login.php and Card_Edit_GetJson.php. Monitor database logs for unusual query patterns or unexpected administrative account activity.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns. Implement strict network segmentation to isolate the access control system from the primary corporate network.
Exploitation Status
Public Exploit Available: Yes, a functional exploit script is available on ExploitDB (EDB-ID: 46833).
Analyst Notes: As of December 26, 2025, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The availability of a public exploit targeting these specific PHP files makes the system highly susceptible to automated attacks.
Analyst Recommendation
Given the critical nature of an access control system and the ease with which this vulnerability can be exploited, it is imperative that administrators take immediate steps to isolate affected devices. Since a vendor patch is not confirmed, the primary defense must be the implementation of strict network access controls and the deployment of WAF signatures to mitigate the risk of remote SQL injection. Failure to secure these systems could result in a total compromise of both digital and physical security perimeters.
Apply vendor patches immediately. Review database access controls and enable query logging.
---METADATA---
VENDOR: ELCA
PRODUCT: Star Transmitter Remote Control
AFFECTED_VERSIONS: Firmware 1.25
CONFIDENCE: high
MISSING: patch
SOURCES_JSON: [{"url":"https://www.elcaradio.com","name":null,"tags":[]},{"url":"https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63209_ELCA%20Star%20Transmitter%20Remote%20Control%20-%20Information%20Disclosure","name":null,"tags":[]}]
PROFILE: batch@eb21ac00f78b
MODEL: gemini-3.1-flash-lite
GENERATED: 2026-08-29T19:15:05.410Z
---END_METADATA---
Description Summary:
ELCA Star Transmitter Remote Control firmware 1.25 contains an information disclosure vulnerability via an unprotected /setup.xml endpoint, allowing unauthenticated retrieval of admin credentials.
Executive Summary:
An unauthenticated information disclosure vulnerability in ELCA Star Transmitter Remote Control firmware 1.25 allows attackers to retrieve administrative credentials and system configuration data.
Vulnerability Details
CVE-ID: CVE-2025-63209
Affected Software: ELCA Star Transmitter Remote Control
Affected Versions: Firmware 1.25
Vulnerability: The system contains an information disclosure flaw where the /setup.xml endpoint is accessible without authentication. This allows an attacker to obtain the administrative password stored in plaintext within the XML tag.
Business Impact
The ability for an unauthenticated user to retrieve administrative credentials poses a critical risk to operational security. With these credentials, an attacker could gain full control over the transmitter system, leading to unauthorized manipulation of remote control functions, potential production downtime, or physical safety hazards. Given the CVSS score of 7.5, this vulnerability represents a high risk to organizational assets.
Remediation Plan
Immediate Action: Contact the vendor, ELCA, to verify if a patched firmware version is available for your specific model, as no public patch is currently confirmed.
Proactive Monitoring: Inspect network traffic for unauthorized access attempts to the /setup.xml endpoint on all affected transmitter hardware.
Compensating Controls: Restrict network access to the transmitter management interface to authorized personnel only, utilizing network segmentation or a firewall to block external access to the vulnerable endpoint.
Exploitation Status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the researcher write-up referenced in the CVE record.
Analyst Notes: As of November 20, 2025, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The vulnerability is highly accessible due to the lack of required authentication for the sensitive endpoint.
Analyst Recommendation
This vulnerability presents a significant risk due to the exposure of administrative credentials. Organizations utilizing ELCA Star Transmitter systems should prioritize isolating these devices from public or untrusted networks immediately. Monitor vendor communications closely for the release of a firmware update and apply it as soon as it becomes available to remediate the underlying flaw.