CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-25211

CVSS 9.8v3.1pub. 2025-03-31upd. 2026-04-15

Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attack may allow an attacker unauthorized access and login.

🤖 AI Analysis
How it works

The vulnerability results from the lack of appropriate requirements regarding password complexity or length (CWE-521 — Weak Password Requirements). An attacker can conduct a brute-force attack, systematically trying successive password combinations until gaining access. Due to the network attack vector (AV:N) and lack of authentication requirements (PR:N) and user interaction (UI:N), the attack is possible remotely and without any prerequisites.

Impact

An attacker can gain unauthorized access to the device and log in, which in an ICS/OT class device can lead to unauthorized viewing or manipulation of production line data, and potentially also disrupt its operation.

Mitigation & patch

Apply patches available from the manufacturer according to references. Additionally, it is recommended to isolate the device from the public network, use strong, unique passwords, and restrict network access to the device using a firewall or OT network segmentation.

Who is affected

CHOCO TEI WATCHER mini (IB-MCT001) — all software versions

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References