PT-2025-47394 · Eurolab · Elts100V1.Ubx+1
Published
2025-11-18
·
Updated
2026-02-04
·
CVE-2025-63225
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eurolab ELTS100 UBX version ELTS100v1.UBX
Description
The Eurolab ELTS100 UBX device is subject to Broken Access Control because of a lack of authentication on critical administrative endpoints. Attackers can directly access and modify sensitive system and network configurations, upload firmware, and execute unauthorized actions without authentication. This allows remote attackers to fully compromise the device, control its functionality, and disrupt its operation.
Recommendations
Apply authentication mechanisms to all critical administrative endpoints to prevent unauthorized access and modification of system configurations and firmware.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elts100 Ubx
Elts100V1.Ubx