CVE-2025-27853
גבוהה 7.3
תיאור (מקור, אנגלית)
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU web site only performs authentication with the client within the client's browser. The WebSockets used to communicate with the WDU server do not enforce any authentication. An attacker may bypass all authentication mechanisms by directly utilizing the remote APIs available on the websocket.
מדדים
- CVSS 3.1
-
7.3 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-4/8/2026
- CWE
- CWE-306
מוצרים מושפעים
garmin: empirbus wireless display unit firmware; garmin: empirbus wireless display unit
קישורים
- https://garmin.com Product
- https://www8.garmin.com/support/ch.jsp?product=010-02642-00 Release Notes