PT-2025-51840 · Netun Solutions · Helpflash Iot

Luis Miranda Acebedo

·

Published

2025-12-17

·

Updated

2026-01-06

·

CVE-2025-65855

CVSS v3.1

6.6

Medium

VectorAV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netun Solutions HelpFlash IoT version v18 178 221102 ASCII PRO 1R5 50
Description The over-the-air (OTA) firmware update process in the software does not properly authenticate update servers or validate firmware signatures, and relies on hard-coded WiFi credentials that are consistent across all devices. An attacker with temporary physical access can initiate the OTA update mode by pressing a button for eight seconds. This allows the attacker to establish a malicious WiFi access point using the known credentials and deliver harmful firmware through unauthenticated HTTP, potentially leading to arbitrary code execution on the device. The device is a safety-critical emergency signaling device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65855

Affected Products

Helpflash Iot