CVE Feed

    Dashboard / CVE / CVE-2025-63225

    CVE-2025-63225

    The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing authentication on critical administrative endpoints. Attackers can directly access and modify sensitive system and network configurations, upload firmware, and execute unauthorized actions without any form of authentication. This vulnerability allows remote attackers to fully compromise the device, control its functionality, and disrupt its operation.

    Published:Nov 18, 2025
    Last Modified:Feb 4, 2026
    EPS:Nov 18, 2025
    EPSS Score:0.00357
    CVSS Score:9.8

    Affected Products

    Vendor
    Eurolab
    Product
    Elts100 Ubx
    Vendor
    Eurolab-srl
    Product
    Elts 100
    Vendor
    Eurolab-srl
    Product
    Elts 100 Firmware

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High