# CVE-2025-0674

## Summary

- **CVE ID:** CVE-2025-0674
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-288
- **Published:** Feb 6, 2025
- **Last Modified:** Mar 13, 2026

## Description

Multiple Elber products are affected by an authentication bypass 
vulnerability which allows unauthorized access to the password 
management functionality. Attackers can exploit this issue by 
manipulating the endpoint to overwrite any user's password within the 
system. This grants them unauthorized administrative access to protected
 areas of the application, compromising the device's system security.

## Affected Products

- Elber — Signum DVB-S/S2 IRD (0)
- Elber — Cleber/3 Broadcast Multi-Purpose Platform (1.0)
- Elber — Reble610 M/ODU XPIC IP-ASI-SDH (0.01)
- Elber — ESE DVB-S/S2 Satellite Receiver (0)
- Elber — Wayber Analog/Digital Audio STL (4)

## References

- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-25-035-03)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 3.65%
- **EPSS Percentile:** 88.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._