PT-2026-3943 · Nerves Hub · Nerveshub
Published
2026-01-22
·
Updated
2026-02-17
·
CVE-2025-64097
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NervesHub versions 1.0.0 through 2.2.9
Description
NervesHub is a web service for managing over-the-air (OTA) firmware updates. A weakness existed where attackers could potentially compromise user API tokens due to their predictable format. These tokens included user-identifiable components and lacked sufficient cryptographic security, making them vulnerable to guessing or enumeration. Successful exploitation could lead to unauthorized access to user accounts and API actions.
Recommendations
NervesHub versions prior to 2.3.0 should be upgraded to version 2.3.0 or later.
As a temporary mitigation, consider firewalling access to the NervesHub server.
Exploit
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nerveshub