CVE-2025-1863 describes critical insecure default settings in various Yokogawa Electric Corporation recorder products, including GX/GP, GM, DX, FX, and μR series, among others. The vulnerability stems from disabled authentication by default, allowing unauthenticated network access to all device functions. This carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability, enabling attackers to manipulate critical data. Despite its severity, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Yokogawa Electric Corporation | CX1000 / CX2000 Paperless Recorders | All versionsCNA affecteddefault unknown | |
| Yokogawa Electric Corporation | DX1000 / DX2000 / DX1000N Paperless Recorders | R4.21 or earlierCNA affecteddefault unknown | |
| Yokogawa Electric Corporation | DX1000T / DX2000T Paperless Recorders | All versionsCNA affecteddefault unknown | |
| Yokogawa Electric Corporation | FX1000 Paperless Recorders | R1.31 or earlierCNA affecteddefault unknown | |
| Yokogawa Electric Corporation | GM Data Acquisition System | R5.05.01 or earlierCNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.