PT-2025-47394 · Eurolab · Elts100V1.Ubx+1

Published

2025-11-18

·

Updated

2026-02-04

·

CVE-2025-63225

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eurolab ELTS100 UBX version ELTS100v1.UBX
Description The Eurolab ELTS100 UBX device is subject to Broken Access Control because of a lack of authentication on critical administrative endpoints. Attackers can directly access and modify sensitive system and network configurations, upload firmware, and execute unauthorized actions without authentication. This allows remote attackers to fully compromise the device, control its functionality, and disrupt its operation.
Recommendations Apply authentication mechanisms to all critical administrative endpoints to prevent unauthorized access and modification of system configurations and firmware.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-63225

Affected Products

Elts100 Ubx
Elts100V1.Ubx