← back
CVE-2025-61956

Missing Authentication for Critical Function in Radiometrics VizAir

CVSS 10 CRITICALEPSS 0.7%CWE-306
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 10EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
04 Nov 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access and API requests. Attackers can modify configurations without authentication, potentially manipulating active runway settings and misleading air traffic control (ATC) and pilots. Additionally, manipulated meteorological data could mislead forecasters and ATC, causing inaccurate flight planning.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Affected products
Radiometrics · VizAir

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →