CVE-2025-47872 Information

Description

The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and unregistered valid but already registered or does not exist in the database. Combined with the fact that serial numbers are sequentially assigned this allows an attacker to gain information on the product registration status of different S/Ns.

Reference

https://eg4electronics.com/contact/ https://www.cisa.gov/news-events/ics-advisories/icsa-25-219-07

CNNVD-202508-760 (Published: 2025-08-08)

Share on: