CVE-2025-8762
A vulnerability was found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This issue affects some unknown processing of the component UART Interface. The manipulation leads to improper physical access control. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.2
- CVSS vector
- CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.18%
- CWE
- CWE-1263, CWE-284
- Published
- 2025-08-13
- Last modified
- 2026-03-12
Affected products
- INSTAR 2K+
- INSTAR 4K
Weakness type
Related vulnerabilities
- CVE-2026-80253 — An improper physical access control issue exists in ShizenBox2 (dev-conf). If exploited, an...
- CVE-2025-4386 — Medtronic MyCareLink Patient Monitor Hardware Debug Port
- CVE-2025-6785 — Tesla Model 3 Physical CAN Bus Injection
- CVE-2024-48973 — Debug port on Life2000 Ventilator serial interface is enabled by default
- CVE-2024-39512 — Junos OS Evolved: User is not logged out when the console cable is disconnected
- CVE-2022-48183
- CVE-2022-48182
- CVE-2022-3728