CVE-2025-5833
Last modified
CVE-2025-5833 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Pioneer DMH-WT7600NEX Root Filesystem Insufficient Verification of Data Authenticity Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of Pioneer DMH-WT7600NEX devices. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
Pioneer DMH-WT7600NEX Root Filesystem Insufficient Verification of Data Authenticity Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the operating system. The issue results from the lack of properly configured protection for the root file system. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-26077.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pioneer | Dmh-Wt7600nex Firmware | 3.05 |
References
- https://www.zerodayinitiative.com/advisories/ZDI-25-350/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-5833?
How severe is CVE-2025-5833?
How do I fix CVE-2025-5833?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-58324An improper neutralization of input during web page generati…4.8
- CVE-2025-58325An Incorrect Provision of Specified Functionality vulnerabil…6.7
- CVE-2025-58326Rejected reason: Not used
- CVE-2025-58327Rejected reason: Not used
- CVE-2025-58328Rejected reason: Not used
- CVE-2025-58329Rejected reason: Not used
- CVE-2025-58330Rejected reason: Not used
- CVE-2025-58331Rejected reason: Not used
- CVE-2025-58332Rejected reason: Not used
- CVE-2025-58333Rejected reason: Not used
- CVE-2025-58334In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.21…8.8
- CVE-2025-58335In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66…7.5
Are you affected by CVE-2025-5833?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
