CVE-2025-57441
9.8Blackmagic Design · ATEM Mini Pro
The Blackmagic ATEM Mini Pro 2.7 exposes sensitive configuration and device information via an unauthenticated Telnet service on port 9990, facilitating unauthorized reconnaissance.
Executive summary
An unauthenticated information disclosure vulnerability in the Blackmagic ATEM Mini Pro 2.7 allows remote attackers to gain sensitive device and stream configuration details.
Vulnerability
This vulnerability involves the exposure of sensitive system data through an unauthenticated Telnet service on port 9990. Attackers can access a protocol preamble containing video modes, routing configurations, input labels, and internal device identifiers without requiring any authentication.
Business impact
The exposure of internal device identifiers and routing configurations poses a significant risk to operational security and network integrity. Given the CVSS score of 9.8, this flaw represents a critical risk as it permits unauthenticated attackers to perform reconnaissance, which is a prerequisite for more sophisticated attacks against the production environment.
Remediation
Immediate Action: Restrict network access to port 9990 via firewall rules to ensure the Telnet service is not exposed to untrusted segments. Contact the vendor for available firmware updates that disable or secure this management interface.
Proactive Monitoring: Monitor network traffic for unauthorized connection attempts to port 9990 and audit logs for unusual Telnet handshake patterns.
Compensating Controls: Implement network segmentation to isolate the ATEM Mini Pro from public or guest networks, ensuring it is only accessible to authorized management workstations.
Exploitation status
Public Exploit Available: Yes (published PoC exists per the research write-up referenced in the CVE record).
Analyst recommendation
Organizations utilizing Blackmagic ATEM Mini Pro devices must treat this as a high-priority security issue. Because the Telnet service provides deep visibility into the device configuration, it is imperative to block port 9990 immediately to prevent unauthorized reconnaissance until a vendor-supplied patch can be applied.
More Blackmagic Design CVEs
History
- Disclosed CVE record published
- Published in the daily brief critical section
- Published in the daily brief critical section
- Analyst report written