CVE-2023-48425 is a critical U-Boot vulnerability affecting Google Chromecast and its firmware, allowing for persistent code execution. With a CVSS score of 9.8, it presents a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog and lacking public exploit code, it has garnered some community discussion and media coverage, indicating awareness of its potential. Despite its high FAUCET Risk Score, its EPSS score suggests a relatively low probability of exploitation in the wild at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023-10-01CPE matchmatch criteria | cpe:2.3:o:google:chromecast_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.