PT-2025-12840 · Unknown · Carlinkit Cpc200-Ccpa

Aaron Luo

+1

·

Published

2025-03-25

·

Updated

2025-04-23

·

CVE-2025-2764

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CarlinKit CPC200-CCPA (affected versions not specified)
Description The issue concerns an improper verification of cryptographic signature, potentially leading to code execution. This has been identified in the update.cgi component.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2025-2764
ZDI-25-178

Affected Products

Carlinkit Cpc200-Ccpa