CVE-2025-10127
7.3Daikin Europe N.V · Security Gateway
Daikin Europe N.V Security Gateway is susceptible to an authorization bypass caused by a user-controlled key, permitting unauthenticated access to the system.
Executive summary
The Daikin Security Gateway contains a critical authorization bypass vulnerability that allows unauthenticated attackers to gain unauthorized access to the device.
Vulnerability
This vulnerability is an authorization bypass (CWE-640) stemming from a user-controlled key flaw. It allows an unauthenticated attacker to bypass security requirements and access the system without providing valid credentials.
Business impact
The ability for an unauthenticated user to bypass authentication represents a severe risk to operational integrity and system confidentiality. Given the CVSS score of 7.3, this flaw enables unauthorized actors to interact with the gateway, potentially leading to unauthorized configuration changes or further exploitation of connected building management systems.
Remediation
Immediate Action: Review the vendor advisory at the provided CISA ICS advisory link to determine the availability of firmware updates and apply them as soon as they are released.
Proactive Monitoring: Monitor network traffic for unusual authentication requests or unexpected access attempts originating from unauthorized IP addresses.
Compensating Controls: Restrict access to the Security Gateway interface by placing it behind a firewall or VPN, ensuring it is not exposed to the public internet.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
This vulnerability presents a significant risk to the security of the Daikin Security Gateway. Administrators should prioritize isolating affected gateways from external network exposure until a vendor-supplied patch is applied. Continuous monitoring of device logs is recommended to detect any attempts to leverage this bypass mechanism.
Sources
Originally found and disclosed by Gjoko Krstic, per the CVE Program record.