CVE-2025-64097 describes a critical vulnerability in NervesHub versions 1.0.0 through 2.2.x, affecting its ability to manage over-the-air firmware updates. Attackers could brute-force user API tokens due to their predictable, non-cryptographically secure format, potentially leading to unauthorized access to user accounts and API actions. With a CVSS score of 9.8 (CRITICAL), this vulnerability allows unauthenticated remote attackers to achieve high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or publicly available exploit code, the vulnerability has garnered significant community discussion, with 10 mentions. Upgrading to NervesHub version 2.3.0, which implements strong, cryptographically random tokens and secure storage, is the only practical remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 2.3.0CPE matchmatch criteria | cpe:2.3:a:nerves-hub:nerveshub:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.