CVE-2025-51040

7.5

Electrolink · FM/DAB/TV Transmitter Web Management System

An unauthorized access vulnerability exists in the Electrolink FM/DAB/TV Transmitter Web Management System via the /FrameSetCore.html endpoint.

Executive summary

A critical unauthorized access vulnerability in the Electrolink Transmitter Web Management System allows unauthenticated attackers to potentially bypass security controls and access sensitive system interfaces.

Vulnerability

This is an unauthorized access flaw affecting the /FrameSetCore.html endpoint, which permits unauthenticated remote attackers to interact with the web management interface without prior login.

Business impact

Successful exploitation of this vulnerability could lead to unauthorized access to transmitter management functions, potentially resulting in the compromise of broadcasting operations or unauthorized configuration changes. With a CVSS score of 7.5, this high-severity flaw presents a significant risk to operational continuity and the integrity of critical infrastructure systems.

Remediation

Immediate Action: Restrict network access to the web management interface by placing it behind a VPN or an isolated management network, as no official vendor patch is currently confirmed.

Proactive Monitoring: Review web server access logs for requests directed at /FrameSetCore.html originating from unauthorized or external IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) or equivalent network filter to block unauthorized requests to the identified vulnerable endpoint until a formal vendor update is applied.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the GitHub repository referenced by the CVE record.

Analyst recommendation

Given the high CVSS score and the presence of a public proof-of-concept, organizations operating affected Electrolink hardware must treat this as an urgent security priority. Administrators should immediately isolate the management interfaces from public or untrusted networks to prevent exploitation while awaiting official guidance or patches from the vendor.

Sources