Home

Description

A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver version drv_gen5_106-01-2380, allows malformed packets to be sent through BACnet MS/TP network causing the devices to enter a fault state. This fault state requires a manual power cycle to return the device to network visibility.

PUBLISHED Reserved 2025-01-22 | Published 2025-11-27 | Updated 2025-11-28 | Assigner Carrier




HIGH: 8.8CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N

Problem types

CWE-129 Improper Validation of Array Index

CWE-248 Uncaught Exception

Product status

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Credits

Christopher Morales Gonzalez reporter

References

www.corporate.carrier.com/...-security/advisories-resources/

cve.org (CVE-2025-0657)

nvd.nist.gov (CVE-2025-0657)

Download JSON