PT-2025-45017 · Radiometrics · Radiometrics Vizair

Souvik Kandar

·

Published

2025-11-04

·

Updated

2025-11-12

·

CVE-2025-61945

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Radiometrics VizAir (affected versions not specified)
Description Radiometrics VizAir is susceptible to unauthorized access to the admin panel, allowing remote attackers to modify critical weather parameters. These parameters include wind shear alerts, inversion depth, and CAPE values, which are crucial for accurate weather forecasting and flight safety. An attacker could disable vital alerts, creating hazardous conditions for aircraft, and manipulate runway assignments, potentially leading to mid-air conflicts or runway incursions. The admin panel is accessible without authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-61945

Affected Products

Radiometrics Vizair