{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-11943","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2025-10-19T02:39:10.333Z","datePublished":"2025-10-19T19:32:05.817Z","dateUpdated":"2025-10-20T19:06:32.308Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2025-10-19T19:32:05.817Z"},"title":"70mai X200 HTTP Web Server default credentials","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-1392","lang":"en","description":"Use of Default Credentials"}]}],"affected":[{"vendor":"70mai","product":"X200","versions":[{"version":"20251010","status":"affected"}],"modules":["HTTP Web Server"]}],"descriptions":[{"lang":"en","value":"A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality of the component HTTP Web Server. The manipulation leads to use of default credentials. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."},{"lang":"de","value":"In 70mai X200 up to 20251010 wurde eine Schwachstelle gefunden. Es betrifft eine unbekannte Funktion der Komponente HTTP Web Server. Durch Manipulieren mit unbekannten Daten kann eine use of default credentials-Schwachstelle ausgenutzt werden. Der Angriff kann remote ausgeführt werden. Die Schwachstelle wurde öffentlich offengelegt und könnte ausgenutzt werden."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":6.9,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":7.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:W/RC:R","baseSeverity":"HIGH"}},{"cvssV3_0":{"version":"3.0","baseScore":7.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:W/RC:R","baseSeverity":"HIGH"}},{"cvssV2_0":{"version":"2.0","baseScore":7.5,"vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:W/RC:UR"}}],"timeline":[{"time":"2025-10-19T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2025-10-19T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2025-10-19T04:44:18.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"geochen (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.329022","name":"VDB-329022 | 70mai X200 HTTP Web Server default credentials","tags":["vdb-entry"]},{"url":"https://vuldb.com/?ctiid.329022","name":"VDB-329022 | CTI Indicators (IOB, IOC)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.672521","name":"Submit #672521 | 70mai dash cam Omni X200 Improper Access Controls","tags":["third-party-advisory"]},{"url":"https://github.com/geo-chen/70mai/blob/main/README.md#finding-10-exposed-root-password-via-unauthenticated-http-server","tags":["exploit"]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-10-20T19:06:14.988312Z","id":"CVE-2025-11943","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-10-20T19:06:32.308Z"}}]}}