CVE Feed

    Dashboard / CVE / CVE-2025-6519

    CVE-2025-6519

    E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modified by any user.

    Published:Sep 2, 2025
    Last Modified:Oct 10, 2025
    EPS:Sep 2, 2025
    EPSS Score:0.00059
    CVSS Score:9.8

    Affected Products

    Vendor
    Copeland
    Product
    E3 Supervisory Controller Firmware
    Vendor
    Copeland
    Product
    Site Supervisor Bx 860-1240
    Vendor
    Copeland
    Product
    Site Supervisor Bxe 860-1245
    Vendor
    Copeland
    Product
    Site Supervisor Cx 860-1260
    Vendor
    Copeland
    Product
    Site Supervisor Cxe 860-1265
    Vendor
    Copeland
    Product
    Site Supervisor Rx 860-1220
    Vendor
    Copeland
    Product
    Site Supervisor Rxe 860-1225
    Vendor
    Copeland
    Product
    Site Supervisor Sf 860-1200

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High