CVE-2025-1425 Details
Description
A Sudo privilege misconfiguration vulnerability in PocketBook InkPad Color 3 on Linux, ARM allows attackers to read file contents on the device.This issue affects InkPad Color 3: U743k3.6.8.3671.
A vulnerability in the PocketBook InkPad Color 3 e-reader running Linux on ARM architecture allows attackers to read file contents from the device. This issue is caused by a misconfiguration in the sudoers file, which permits the user 'reader' to execute the 'ntpdate' command with root privileges. The vulnerability affects InkPad Color 3 model U743k3.6.8.3671.
It is recommended to remove the 'ntpdate' utility from the sudoers configuration and to implement additional security measures such as requiring a device unlock password at boot.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 4, 2025CISA-ADP
Assessed Mar 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.redguard.ch/blog/2025/03/04/security-advisory-pocketbook-inkpad-color-3/ | [email protected] | AdvisoryBundleExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| PocketBook InkPad Color 3 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 4, 2025 | New CVE Received | [email protected] |
Volerion