PT-2025-17668 · Byd · Byd Qin Plus Dm-I Dilink Os

Rainymode

·

Published

2025-04-23

·

Updated

2025-04-28

·

CVE-2025-28169

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BYD QIN PLUS DM-i Dilink OS versions v3.0 13.1.7.2204050.1 through v3.0 13.1.7.2312290.1 0
Description The issue allows attackers to execute a man-in-the-middle attack because the affected software sends broadcasts to the manufacturer's cloud server unencrypted.
Recommendations For versions v3.0 13.1.7.2204050.1 through v3.0 13.1.7.2312290.1 0, consider implementing encryption for broadcasts to the cloud server as a mitigation measure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2025-28169

Affected Products

Byd Qin Plus Dm-I Dilink Os