The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing authentication on critical administrative endpoints. Attackers can directly access and modify sensitive system and network configurations, upload firmware, and execute unauthorized actions without any form of authentication. This vulnerability allows remote attackers to fully compromise the device, control its functionality, and disrupt its operation.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eurolab-srl
Eurolab-srl elts 100 Eurolab-srl elts 100 Firmware |
|
| CPEs | cpe:2.3:h:eurolab-srl:elts_100:e118:*:*:*:*:*:*:* cpe:2.3:o:eurolab-srl:elts_100_firmware:elts100v1.ubx:*:*:*:*:*:*:* |
|
| Vendors & Products |
Eurolab-srl
Eurolab-srl elts 100 Eurolab-srl elts 100 Firmware |
Thu, 20 Nov 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eurolab
Eurolab elts100 Ubx |
|
| Vendors & Products |
Eurolab
Eurolab elts100 Ubx |
Wed, 19 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Tue, 18 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing authentication on critical administrative endpoints. Attackers can directly access and modify sensitive system and network configurations, upload firmware, and execute unauthorized actions without any form of authentication. This vulnerability allows remote attackers to fully compromise the device, control its functionality, and disrupt its operation. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-18T00:00:00.000Z
Updated: 2025-11-19T18:50:14.448Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63225
Updated: 2025-11-19T18:49:20.662Z
Status : Analyzed
Published: 2025-11-18T19:15:50.823
Modified: 2026-02-04T20:54:01.817
Link: CVE-2025-63225
No data.