CNNVD-202506-2997 Information

CNNVD ID

CNNVD-202506-2997

CVE-2025-6525

  • CNNVD Published: 2025-06-23

Description (Chinese)

70mai 1S是中国70迈(70mai)公司的一款智能记录仪。 70mai 1S 20250611及之前版本存在安全漏洞,该漏洞源于对文件/cgi-bin/Config.cgi?action=set的错误操作导致授权不当。

Description (English)

70mai 1S is a smart recorder for a 70mai company in China. There is a security loophole in 70mai 1S-20250611 and earlier versions, which stems from the mishandling of document/cgi-bin/Config.cgi?action=set, resulting in improper delegation of authority.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

70迈

Published

2025-06-23

Last Modified

2026-02-24

References

https://github.com/geo-chen/70mai/blob/main/README.md#finding-3-unauthorised-configuration-change https://vuldb.com/?submit.595446 https://vuldb.com/?ctiid.313642 https://vuldb.com/?id.313642 https://access.redhat.com/security/cve/cve-2025-6525

Share on: