PT-2025-48770 · Iskra · Ihub+1

Souvik Kandar

·

Published

2025-12-02

·

Updated

2026-01-09

·

CVE-2025-13510

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Iskra iHUB and iHUB Lite (affected versions not specified)
Description The Iskra iHUB and iHUB Lite smart metering gateway’s web management interface is accessible without authentication. This allows unauthenticated users to access and modify critical device settings. The gateway exposes its admin panel with no authentication required, potentially enabling network pivoting into critical infrastructure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-13510

Affected Products

Ihub
Ihub Lite