CVE-2015-7931 describes a critical vulnerability in the Java client of Adcon Telemetry A840 Telemetry Gateway Base Station firmware. The flaw stems from a lack of authentication for station devices and missing SSL support, enabling man-in-the-middle attackers to spoof devices and intercept sensitive cleartext data. With a CVSS score of 8.7 (HIGH), this vulnerability presents a significant risk due to its network-based attack vector, high confidentiality and integrity impacts, and relatively low attack complexity. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity landscape, though it is not currently on the KEV catalog or considered actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:adcon:a840_telemetry_gateway_base_station_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.