CVE-2025-43928 is a critical directory traversal vulnerability affecting Infodraw Media Relay Service (MRS) 7.1.0.0 and related products (pmrs_102, pmrs_102_firmware). An unauthenticated attacker can exploit this flaw by manipulating the username field on the MRS web server (port 12654) to read arbitrary files, including ServerParameters.xml which may contain cleartext or MD5-hashed administrator credentials. This vulnerability carries a CVSS score of 9.8 (Critical), indicating a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. The EPSS score is low, suggesting a low probability of exploitation in the wild, but the FAUCET Risk Score is 95/100. While there is no known active exploitation, exploit code (Metasploit, Nuclei, ExploitDB) is not publicly available, and it is not listed in the CISA KEV catalog, there is significant community discussion surrounding this CVE, including a recent presentation on the vulnerability and the challenges in vendor remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.1.0.0CPE matchmatch criteria | cpe:2.3:o:infodraw:pmrs-102_firmware:7.1.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.