PT-2025-38741 · Blackmagic Design · Blackmagic Web Presenter

Published

2025-09-22

·

Updated

2025-09-22

·

CVE-2025-57432

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Blackmagic Web Presenter version 3.3
Description The software exposes a Telnet service on port 9977 that accepts unauthenticated commands. This allows remote attackers to manipulate stream settings, potentially changing video modes and altering device functionality. No authentication is required to interact with the Telnet interface.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-57432

Affected Products

Blackmagic Web Presenter