PT-2025-20853 · Ozw772+1 · Ozw772+1

Published

2025-05-13

·

Updated

2025-05-13

·

CVE-2025-26390

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions: OZW672 versions prior to V6.0 OZW772 versions prior to V6.0
Description: A vulnerability has been identified in the web service of affected devices, making it vulnerable to SQL injection when checking authentication data. This could allow an unauthenticated remote attacker to bypass the check and authenticate as an Administrator user.
Recommendations: For OZW672 versions prior to V6.0, update to version V6.0 or later to resolve the issue. For OZW772 versions prior to V6.0, update to version V6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the web service to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-06524
CVE-2025-26390

Affected Products

Ozw672
Ozw772