CVE-2025-9056 describes an unprotected service within the AudioLink component of tecno audiolink products, enabling a local attacker to overwrite system files through unauthorized service invocation. Rated as MEDIUM severity (CVSS 5.3), this vulnerability has a network attack vector and low attack complexity, potentially leading to a loss of system integrity. While the EPSS score is very low and it is not listed in KEV, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has received no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.0.87CPE matchmatch criteria | cpe:2.3:a:tecno:audiolink:1.3.0.87:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.