CVE-2024-25972 describes an insecure default vulnerability in the OET-213H-BTS1 product sold in Japan by Atsumi Electric Co., Ltd., allowing an unauthenticated, network-adjacent attacker to gain full control over the device. With a CVSS score of 8.3 (High), this vulnerability presents a significant risk due to its low attack complexity and potential for high impact on confidentiality and integrity, alongside a partial impact on availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Zhejiang Uniview Technologies Co.,Ltd And Atsumi Electric Co., Ltd. | OET-213H-BTS1 | all firmware versionsCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.