CVE detail
CVE-2025-59460
The system is deployed in its default state, with configuration settings that do not comply with the latest best practices for restricting access. This increases the risk of unauthorised connections.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 16.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
No excerpt available.
Vendor Advisorywww.sick.comOct 27, 2025, 11:15 AMNo excerpt available.
Vendor Advisorywww.sick.comOct 27, 2025, 11:15 AMNo excerpt available.
Vendor Advisorywww.sick.comOct 27, 2025, 11:15 AM- https://www.first.org/cvss/calculator/3.1www.first.org
No excerpt available.
Not Applicablewww.first.orgOct 27, 2025, 11:15 AM No excerpt available.
Mitigationwww.cisa.govOct 27, 2025, 11:15 AM- https://sick.com/psirtsick.com
No excerpt available.
Vendor Advisorysick.comOct 27, 2025, 11:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-59463CVSS 4.3 · Medium
An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers.
- CVE-2025-59462CVSS 6.5 · Medium
An attacker who tampers with the C++ CLI client may crash the UpdateService during file transfers, disrupting updates and availability.
- CVE-2025-59461CVSS 7.6 · High
A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.
- CVE-2025-59459CVSS 5.5 · Medium
An attacker that gains SSH access to an unprivileged account may be able to disrupt services (including SSH), causing persistent loss of availability.
- CVE-2026-66409CVSS 6.9 · Medium
DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to connect to the access point o…
- CVE-2026-66408CVSS 5.1 · Medium
The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected product may allow to obtain the password of the root ac…