CVE-2025-53520
Last modified
CVE-2025-53520 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks. The TTComp archive format used for the firmware is unencrypted and can be unpacked and altered without detection.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks. The TTComp archive format used for the firmware is unencrypted and can be unpacked and altered without detection.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-53520?
How severe is CVE-2025-53520?
How do I fix CVE-2025-53520?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-53515A vulnerability exists in Advantech iView that allows for SQ…8.8
- CVE-2025-53516A reflected cross-site scripting (xss) vulnerability exists …6.1
- CVE-2025-53517Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2025-53518An integer overflow vulnerability exists in the ABF parsing …9.8
- CVE-2025-53519A vulnerability exists in Advantech iView versions prior to …5.4
- CVE-2025-5352A critical stored Cross-Site Scripting (XSS) vulnerability e…9.6
- CVE-2025-53521When a BIG-IP APM access policy is configured on a virtual s…9.8
- CVE-2025-53522Movable Type contains an issue with use of less trusted sour…6.9
- CVE-2025-53523Stored cross-site scripting vulnerabilities exist in GroupSe…5.4
- CVE-2025-53524Fuji Electric Monitouch V-SFT-6 is vulnerable to an out-of-b…8.4
- CVE-2025-53525WeGIA is a web manager for charitable institutions. A Reflec…6.1
- CVE-2025-53526WeGIA is a web manager for charitable institutions. An XSS I…6.1
Are you affected by CVE-2025-53520?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
