← Back to browse · API

CVE-2025-63207

Severity
CRITICAL
CVSS
9.8
EPSS
0.0697
Risk score
41.64
CISA KEV
No
PoC
No
Published
2025-11-19
Modified
2025-11-20
First seen
2026-08-07
Aliases
EUVD-2025-198191, GHSA-PPM2-7RR7-H984
Products
n/a:n/a n/a
Sources
euvd EUVD-2025-198191

Description

The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system compromise.

References