← back
CVE-2025-2859mediumCWE-287

Improper Authentication vulnerability in saTECH BCU

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.9epss 0.4%
exploitation probability
0.4%top 66% of all CVEs
observed exploitation
nono source reports it
An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the active user session and make changes to the device via web, depending on the privileges obtained by the user.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
Arteche · saTECH BCU