CVE-2025-5437 Details
Description
A vulnerability classified as critical has been found in Multilaser Sirius RE016 MLT1.0. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the component Password Change Handler. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A critical vulnerability has been identified in the Multilaser Sirius RE016 MLT1.0 model, specifically within an unknown function of the file '/cgi-bin/cstecgi.cgi', which handles password changes. This vulnerability allows for improper authentication and can be exploited remotely. The issue has been publicly disclosed, and the vendor was contacted prior to this disclosure but did not respond.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 2, 2025CISA-ADP
Assessed Jun 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/DefaultCh40s/RE016/blob/main/re016.py | [email protected] | Exploit |
| https://vuldb.com/?ctiid.310770 | [email protected] | Content Wall |
| https://vuldb.com/?id.310770 | [email protected] | Content Wall |
| https://vuldb.com/?submit.584325 | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Multilaser Sirius RE016 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2025 | New CVE Received | [email protected] |
Volerion