CRITICAL🇵🇱 Wersja polska

CVE-2025-27851

CVSS 9.3pub. 2026-05-13upd. 2026-06-02

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU utilizes WebSockets to control settings, including administrative settings. This allows a network attacker to take full control of a WDU. To initiate an exploit of this vulnerability, the victim must (1) be utilizing a web browser on a multihomed host that has local interfaces on the Garmin Marine Network as well as another network, and (2) access a malicious third party website created by the attacker.

🤖 AI Analysis
How it works

The Garmin WDU device hosts a local website that uses the WebSocket protocol for settings management, including administrative settings. The vulnerability results from lack of proper verification of the origin of WebSocket requests (CWE-352 — Cross-Site Request Forgery). The attack requires the victim to use a browser on a host connected simultaneously to both the Garmin Marine Network and another network (multi-interface host), and then visit a malicious website prepared by the attacker. The malicious website initiates a WebSocket connection to the local interface of the WDU device, bypassing browser isolation mechanisms.

Impact

The attacker gains full control over the Garmin WDU device, including the ability to modify administrative settings, which may lead to violation of confidentiality and integrity of data transmitted or stored by the device.

Mitigation & patch

Apply patches available from the manufacturer according to references. As a workaround, avoid using a web browser on hosts connected simultaneously to both the Garmin Marine Network and other external networks, especially when browsing untrusted websites.

Who is affected

Garmin WDU v1 firmware version 1.4.6 and Garmin WDU v2 firmware version 5.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Garmin Empirbus Wireless Display Unit

    HW
    Garmin
    v1v2
  • Garmin Empirbus Wireless Display Unit Firmware

    OS
    Garmin
    1.4.65.00
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-27850HIGH7.5same product

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious gr...

CVE-2025-27853HIGH7.3same product

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. ...

CVE-2025-27852MEDIUM5.0same product

Lokalnie obsługiwana strona internetowa na urządzeniu Garmin WDU (wersje v1 1.4.6 i v2 5.0) jest podatna na re...

CVE-2023-23298CRITICAL9.8PL ✓same vendor

Integer overflow w Garmin Connect-IQ API — przejęcie firmware urządzenia

CVE-2023-23300CRITICAL9.8PL ✓same vendor

Buffer overflow w Garmin Connect-IQ API — przejęcie firmware urządzenia