PT-2025-32369 · Eg4 · Eg4
Anthony Rose
·
Published
2025-08-08
·
Updated
2025-08-13
·
CVE-2025-53520
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EG4 (affected versions not specified)
Description
The affected product allows firmware updates to be downloaded from EG4’s website, transferred via USB dongles, or installed through EG4’s Monitoring Center (remote, cloud-connected interface) or via a serial connection. These files are installed without integrity checks. The TTComp archive format used for the firmware is unencrypted and can be unpacked and altered without detection.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eg4