CVE-2025-65855 - Netun Solutions HelpFlash IoT Firmware Hard-Coded WiFi Credentials Unauthenticat...
CVE ID : CVE-2025-65855 Published : Dec. 17, 2025, 5:15 p.m. | 1 hour, 36 minutes ago Description : The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentials identical across all devices and does not authenticate update servers or validate firmware signatures. An attacker with brief physical access can activate OTA mode (8-second button press), create a malicious WiFi AP using the known credentials, and serve malicious firmware via unauthenticated HTTP to achieve arbitrary code execution on this safety-critical emergency signaling device. Severity: 6.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Source: Telegram CVE Monitor