CVE-2025-28203
Published May 9, 2025Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
4 CVEs tagged to govicture / rx1800_firmware — 1 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.
Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services without authentication.
An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain root access.
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.