The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing authentication on critical administrative endpoints. Attackers can directly access and modify sensitive system and network configurations, upload firmware, and execute unauthorized actions without any form of authentication. This vulnerability allows remote attackers to fully compromise the device, control its functionality, and disrupt its operation.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Nov 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eurolab
Eurolab elts100 Ubx |
|
| Vendors & Products |
Eurolab
Eurolab elts100 Ubx |
Wed, 19 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Tue, 18 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing authentication on critical administrative endpoints. Attackers can directly access and modify sensitive system and network configurations, upload firmware, and execute unauthorized actions without any form of authentication. This vulnerability allows remote attackers to fully compromise the device, control its functionality, and disrupt its operation. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-18T00:00:00.000Z
Updated: 2025-11-19T18:50:14.448Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63225
Updated: 2025-11-19T18:49:20.662Z
Status : Awaiting Analysis
Published: 2025-11-18T19:15:50.823
Modified: 2025-11-19T19:15:49.587
Link: CVE-2025-63225
No data.