CVE-2025-63207

The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system compromise.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:rvr:tex30lcd\/s_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex30lcd\/s:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:rvr:tex50lcd\/s_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex50lcd\/s:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:rvr:tex100lcd\/s_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex100lcd\/s:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:rvr:tex150lcd\/s_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex150lcd\/s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:rvr:tex300lcd_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex300lcd:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:rvr:tex502lcd_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex502lcd:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:rvr:tex702lcd_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex702lcd:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:rvr:tex3500lcd_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex3500lcd:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:rvr:tex1002lcd_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex1002lcd:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:rvr:tex2000light_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex2000light:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:rvr:tex2500lcd_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex2500lcd:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-11-19 18:15

Updated : 2026-01-15 19:55


NVD link : CVE-2025-63207

Mitre link : CVE-2025-63207

CVE.ORG link : CVE-2025-63207


JSON object : View

Products Affected

rvr

  • tex50lcd\/s_firmware
  • tex50lcd\/s
  • tex2000light
  • tex100lcd\/s_firmware
  • tex502lcd_firmware
  • tex2000light_firmware
  • tex2500lcd
  • tex502lcd
  • tex100lcd\/s
  • tex2500lcd_firmware
  • tex702lcd_firmware
  • tex150lcd\/s_firmware
  • tex3500lcd_firmware
  • tex300lcd_firmware
  • tex1002lcd
  • tex1002lcd_firmware
  • tex30lcd\/s_firmware
  • tex150lcd\/s
  • tex300lcd
  • tex30lcd\/s
  • tex702lcd
  • tex3500lcd
CWE
CWE-287

Improper Authentication