CRITICAL
UDP Service Weak Authentication
Published Sep 23, 2025
9.3
CRITICALCVSS 4.0
EPSS 0.55%
Description
Improper authentication vulnerability in Novakon P series allows unauthenticated attackers to upload and download any application from/to the device.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).
Affected products
-
- Version P – V2001.A.c518o2StatusaffectedConstraints<=P-V2005
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Novakon | P series (P07, P10, P12, P15) | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://seclists.org/fulldisclosure/2025/Sep/70
- https://cyberdanube.com/security-research/multiple-vulnerabilities-in-novakon-hmi-series/
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-30880 Advisory
- https://www.novakon.com.tw/common/frontend/download?path=/uploads/images/support/download/NOVAKON_P-Series-HMI_Security-Advisory_CVE-2025-9962-9966_Rev2_0.pdf vendor-advisory
- https://www.novakon.com.tw/en/news/detail/Security_Advisory__Firmware_Update_Available_for_NOVAKON_P_Series_HMI_Products vendor-advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CyberDanube
Published Sep 23, 2025
Updated Mar 31, 2026
Reserved Sep 3, 2025
Link CVE-2025-9965
CISA Vulnrichment
Updated Sep 23, 2025
ENISA EUVD
EUVD-2025-30880 Assigner CyberDanube
Published Sep 23, 2025
Updated Mar 31, 2026
Exploited since n/a
Link EUVD-2025-30880