# CVE-2025-22450

## Summary

- **CVE ID:** CVE-2025-22450
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
- **CWE:** CWE-1242
- **Published:** Jan 22, 2025
- **Last Modified:** Mar 13, 2026

## Description

Inclusion of undocumented features issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. A remote attacker may disable the LAN-side firewall function of the affected products, and open specific ports.

## Affected Products

- I-O DATA DEVICE, INC. — UD-LT2 (firmware Ver.1.00.008_SE and earlier)

## References

- [CNA](https://www.iodata.jp/support/information/2025/01_ud-lt2/)
- [CNA](https://jvn.jp/en/jp/JVN15293958/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.38%
- **EPSS Percentile:** 31.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._