CVE-2025-0657 is a high-severity vulnerability (CVSS 8.8) affecting Automated Logic and Carrier i-Vu Gen5 routers running driver version drv_gen5_106-01-2380. Malformed BACnet MS/TP packets can trigger a fault state, requiring a manual power cycle to restore network visibility. This unauthenticated attack is network-exploitable with low complexity, potentially causing denial of service. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Automated Logic | WebCtrl | >= 0, <= 8.5CNA affecteddefault unaffected | |
| Carrier | I-Vu | >= 0, <= 8.5CNA affecteddefault unaffected | |
| Automated Logic | Gen5 Controllers | >= 0, <= drv_gen5_108-04-20120CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.