CVE-2025-5484
Last modified
CVE-2025-5484 is a high-severity vulnerability rated 8.3/10 on the CVSS scale. A username and password are required to authenticate to the central SinoTrack device management interface. The username for all devices is an identifier printed on the receiver. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
A username and password are required to authenticate to the central SinoTrack device management interface. The username for all devices is an identifier printed on the receiver. The default password is well-known and common to all devices. Modification of the default password is not enforced during device setup. A malicious actor can retrieve device identifiers with either physical access or by capturing identifiers from pictures of the devices posted on publicly accessible websites such as eBay.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-5484?
How severe is CVE-2025-5484?
How do I fix CVE-2025-5484?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-54831Apache Airflow 3 introduced a change to the handling of sens…6.5
- CVE-2025-54832OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0,…5.3
- CVE-2025-54833OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 a…7.5
- CVE-2025-54834OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 a…6.9
- CVE-2025-54838An Incorrect Authorization vulnerability [CWE-863] in FortiP…6.5
- CVE-2025-54839Rejected reason: Not used
- CVE-2025-54840Rejected reason: Not used
- CVE-2025-54841Rejected reason: Not used
- CVE-2025-54842Rejected reason: Not used
- CVE-2025-54843Rejected reason: Not used
- CVE-2025-54844Rejected reason: Not used
- CVE-2025-54845Rejected reason: Not used
Are you affected by CVE-2025-5484?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
