CRITICAL🇵🇱 Wersja polska

CVE-2025-30184

CVSS 9.3v4.0pub. 2025-06-09upd. 2025-08-12

CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.

🤖 AI Analysis
How it works

The error classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel) lies in the fact that the authentication mechanism is not enforced for all access paths to the device's web interface. An attacker can reach the protected management interface by bypassing the standard login procedure through an unprotected alternate URL path or access channel. The attack requires no permissions, user interaction, or complex conditions — network access to the device is sufficient.

Impact

An unauthenticated attacker gains full access to the device's web interface, which may enable takeover of intercom configuration, modification of SIP settings, disruption of emergency communications, or further network activities.

Mitigation & patch

Apply patches available from the manufacturer according to references. Detailed information about firmware updates is contained in the CISA ICS-CERT advisory numbered ICSA-25-155-01 (https://www.cisa.gov/news-events/ics-advisories/icsa-25-155-01). Until the patch is deployed, it is recommended to restrict network access to the device's management interface exclusively to trusted hosts/networks, for example through firewall or network segmentation.

Who is affected

CyberData 011209 SIP Emergency Intercom and related firmware software (versions indicated in manufacturer references / CISA advisory ICSA-25-155-01)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Cyberdata 011209 Sip Emergency Intercom

    HW
    Cyberdata
    all versions
  • Cyberdata 011209 Sip Emergency Intercom Firmware

    OS
    Cyberdata
    < 22.0.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-30515CRITICAL9.3PL ✓same product

CyberData 011209 SIP Intercom — nieautoryzowane przesyłanie plików (path traversal)

CVE-2025-26468HIGH8.7same product

CyberData  011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a...

CVE-2025-30183HIGH8.7same product

CyberData 011209 Intercom does not properly store or protect web server admin credentials.

CVE-2025-30507MEDIUM6.9same product

CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQ...