CVE-2025-14095 is a "Privilege boundary violation" vulnerability affecting multiple Radiometer Products, allowing an attacker with physical access to gain unauthorized functionality. The severity is rated Medium (CVSS 6.8 or 5.7 depending on the OS), as it requires physical access but can lead to high confidentiality, integrity, and availability impact. While researchers have developed proof-of-concept exploits, Radiometer is not aware of any public exploits, and there is minimal community discussion or media coverage. A temporary workaround involves restricting physical access to authorized personnel, with a permanent solution to be provided by local Radiometer representatives.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Radiometer Medical Aps | ABL800 BASIC And ABL800 FLEX Analyzers | Application software versions < 6.20 MR2 with Windows 10 as underlying OS, Application software versions < 6.20 MR2 with Windows 7, Windows XP as underlying OSCNA affecteddefault unaffected | |
| Radiometer Medical Aps | ABL9 Analyzers | Application software versions < 1.5.0CNA affecteddefault unaffected | |
| Radiometer Medical Aps | ABL90 FLEX And ABL90 FLEX PLUS Analyzers | All application software versions with Windows 7, Windows XP as underlying OS, Application software versions < 3.5MR11 with Windows 10 as underlying OSCNA affecteddefault unaffected | |
| Radiometer Medical Aps | AQT90 FLEX Analyzers | All Application software versions <= 8.13 MR2CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.