CVE-2025-36755
The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under normal operating conditions. Researchers demonstrated that, after cicumventing the device’s protective enclosure, it was possible to connect a USB keyboard and press ESC during boot to access the BIOS setup interface. BIOS settings could be viewed but not modified. This behavior slightly increases the attack surface by exposing internal system information (CWE-1244) once the enclosure is removed, but does not allow integrity or availability compromise under standard or tested configurations.
Scoring
- Severity
- LOW
- CVSS base score
- 2.4
- CVSS vector
- CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/S:N/AU:N/V:D/RE:L/U:Green
- EPSS probability
- 0.17%
- CWE
- CWE-1244, CWE-1191
- Published
- 2025-12-12
- Last modified
- 2026-03-13
Affected products
- CleverDisplay B.V. BlueOne (CleverDisplay Hardware Player)
- CleverDisplay B.V. BlueOne (CleverDisplay Hardware Player)
Weakness type
Related vulnerabilities
- CVE-2026-8989 — Open Recovery Mode
- CVE-2025-67862 — An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244]...
- CVE-2025-42878 — Sensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM)
- CVE-2025-23337 — NVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC)...
- CVE-2025-23302 — NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the LS10 could enable an...
- CVE-2025-23301 — NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the VBIOS could enable an...
- CVE-2025-20238 — A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco...
- CVE-2025-23252 — The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to...