CVE-2025-7213
A vulnerability classified as critical has been found in FNKvision FNK-GU2 up to 40.1.7. Affected is an unknown function of the component UART Interface. The manipulation leads to on-chip debug and test interface with improper access control. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.4
- CVSS vector
- CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.17%
- CWE
- CWE-1191
- Published
- 2025-07-09
- Last modified
- 2026-03-12
Affected products
- FNKvision FNK-GU2
- FNKvision FNK-GU2
- FNKvision FNK-GU2
- FNKvision FNK-GU2
- FNKvision FNK-GU2
- FNKvision FNK-GU2
- FNKvision FNK-GU2
- FNKvision FNK-GU2
Weakness type
Related vulnerabilities
- CVE-2026-15203 — Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software
- CVE-2026-8989 — Open Recovery Mode
- CVE-2026-8988 — Access to Bootloader
- CVE-2024-36319 — Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to...
- CVE-2025-52533 — Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a...
- CVE-2025-15083 — TOZED ZLT M30s UART on-chip debug and test interface with improper access control
- CVE-2025-36755 — CleverDisplay BlueOne unauthorized BIOS access through physical USB keyboard
- CVE-2025-12114 — Serial Console Enabled