Back to overview

CVE-2025-29270

CRITICAL Exploitation: PoC
10.0
CVSS 3.1
Description
Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the admin panel and complete control of the device.

Metadata

CVE ID
CVE-2025-29270
State
PUBLISHED
Assigner
mitre
Reserved
2025-03-11 00:00 UTC
Published
2025-10-31 00:00 UTC
Last updated
2025-10-31 19:20 UTC
Primary CWE
CWE-200
CWE-200 Exposure of Sensitive Information to an Unauthorized…
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
CWE-200 adp CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CWE-284 adp CWE-284 Improper Access Control
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview