The public-facing product registration endpoint server responds
differently depending on whether the S/N is valid and unregistered,
valid but already registered, or does not exist in the database.
Combined with the fact that serial numbers are sequentially assigned,
this allows an attacker to gain information on the product registration
status of different S/Ns.
References
Configurations
No configuration.
History
08 Aug 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-08 17:15
Updated : 2025-08-08 20:30
NVD link : CVE-2025-47872
Mitre link : CVE-2025-47872
CVE.ORG link : CVE-2025-47872
JSON object : View
Products Affected
No product.
CWE
CWE-203
Observable Discrepancy