CVE-2025-61976
7.5Inaba Denki Sangyo Co., Ltd. · CHOCO TEI WATCHER mini (IB-MCT001)
The CHOCO TEI WATCHER mini (IB-MCT001) is susceptible to a denial of service vulnerability via a crafted request to the Video Download interface.
Executive summary
A critical denial of service vulnerability in the CHOCO TEI WATCHER mini allows unauthenticated remote attackers to render the device unresponsive.
Vulnerability
The device fails to properly check for unusual or exceptional conditions when processing requests to the Video Download interface. An unauthenticated remote attacker can exploit this flaw to cause a system crash or state of unresponsiveness.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk due to its potential for total service disruption. Successful exploitation results in the device becoming unresponsive, which causes significant operational downtime and renders security monitoring capabilities ineffective until a manual reboot or recovery is performed.
Remediation
Immediate Action: Monitor the vendor portal for the release of a firmware update and apply it immediately upon availability. As no patch is currently identified, limit network exposure of the device to trusted segments only.
Proactive Monitoring: Review system logs for unusual spikes in request traffic directed at the Video Download interface. Alert security teams if the device exhibits signs of instability or frequent service interruptions.
Compensating Controls: Deploy a Web Application Firewall or network access control list to restrict access to the affected device interface to authorized IP addresses only.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high impact of this vulnerability on device availability, organizations should treat this as a priority issue. Until a firmware patch is released by the manufacturer, strict network segmentation is the most effective method to prevent unauthorized access and potential exploitation.