CVE-2025-59409 describes a critical vulnerability in Flock Safety Falcon and Sparrow License Plate Readers where development Wi-Fi credentials ("test_flck") are stored in cleartext within production firmware (OPM1.171019.026). This presents a high-severity risk (CVSS 7.5) due to an unauthenticated network attack vector, allowing potential attackers to gain unauthorized access to the devices and compromise confidentiality. While no active exploitation, public exploits, or significant community discussion have been observed, the cleartext credentials pose a significant security flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:flocksafety:license_plate_reader_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.