PT-2025-32369 · Eg4 · Eg4

Anthony Rose

·

Published

2025-08-08

·

Updated

2025-08-13

·

CVE-2025-53520

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EG4 (affected versions not specified)
Description The affected product allows firmware updates to be downloaded from EG4’s website, transferred via USB dongles, or installed through EG4’s Monitoring Center (remote, cloud-connected interface) or via a serial connection. These files are installed without integrity checks. The TTComp archive format used for the firmware is unencrypted and can be unpacked and altered without detection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-53520

Affected Products

Eg4