CVE-2025-63225
Last modified
CVE-2025-63225 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing authentication on critical administrative endpoints. Attackers can directly access and modify sensitive system and network configurations, upload firmware, and execute unauthorized actions without any form of authentication. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing authentication on critical administrative endpoints. Attackers can directly access and modify sensitive system and network configurations, upload firmware, and execute unauthorized actions without any form of authentication. This vulnerability allows remote attackers to fully compromise the device, control its functionality, and disrupt its operation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eurolab-Srl | Elts 100 Firmware | elts100v1.ubx |
References
- http://eurolab-srl.com/Product
- https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63225_Eurolab_ELTS100_UBX_Broken_Access_ControlExploit, Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-63225?
How severe is CVE-2025-63225?
How do I fix CVE-2025-63225?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-63219The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServe…7.5
- CVE-2025-6322A vulnerability was found in PHPGurukul Pre-School Enrollmen…9.8
- CVE-2025-63220The Sound4 FIRST web-based management interface is vulnerabl…7.2
- CVE-2025-63221The Axel Technology puma devices (firmware versions 0.8.5 to…9.1
- CVE-2025-63223The Axel Technology StreamerMAX MK II devices (firmware vers…9.8
- CVE-2025-63224The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to …10
- CVE-2025-63226The Sencore SMP100 SMP Media Platform (firmware versions V4.…5.7
- CVE-2025-63227The Mozart FM Transmitter web management interface on versio…7.2
- CVE-2025-63228The Mozart FM Transmitter web management interface on versio…9.8
- CVE-2025-63229The Mozart FM Transmitter web management interface on versio…5.4
- CVE-2025-6323A vulnerability was found in PHPGurukul Pre-School Enrollmen…9.8
- CVE-2025-63235In sol commit 373d848 (2024-12-12), the broker does not full…7.5
Are you affected by CVE-2025-63225?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
