← back
CVE-2025-27595criticalCWE-328

Weak hashing alghrythm

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
In short

The device uses a weak hashing algorithm to store passwords, making it easy for attackers to crack them and gain unauthorized access to the system.

Technical detail

CWE-328: Use of Insufficiently Random Values. The device implements weak cryptographic hashing for password storage, enabling offline brute-force attacks with low computational cost. Compromise of password hashes allows rapid authentication bypass and full system access.

Summary generated and translated by AI from the official description.
The device uses a weak hashing alghorithm to create the password hash. Hence, a matching password can be easily calculated by an attacker. This impacts the security and the integrity of the device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H