CVE-2025-64305

MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vendor secrets. An attacker can utilize these plaintext secrets to modify the vendor firmware, or gain admin access to the web portal.
Configurations

No configuration.

History

No history.

Information

Published : 2026-01-07 21:15

Updated : 2026-01-08 18:08


NVD link : CVE-2025-64305

Mitre link : CVE-2025-64305

CVE.ORG link : CVE-2025-64305


JSON object : View

Products Affected

No product.

CWE
CWE-313

Cleartext Storage in a File or on Disk