Home

Description

The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system compromise.

PUBLISHED Reserved 2025-10-27 | Published 2025-11-19 | Updated 2025-11-20 | Assigner mitre

References

github.com/...3207_RVR Elettronica TEX Broken Access Control exploit

www.rvr.it/en/

github.com/...3207_RVR Elettronica TEX Broken Access Control

cve.org (CVE-2025-63207)

nvd.nist.gov (CVE-2025-63207)

Download JSON