CVE-2025-63223 Details
Description
The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and modify system settings, leading to full compromise of the device.
A broken access control vulnerability has been identified in Axel Technology StreamerMAX MK II devices running firmware versions 0.8.5 prior to 1.0.3. The vulnerability arises from missing authentication on the '/cgi-bin/gstFcgi.fcgi' endpoint, allowing unauthenticated remote attackers to access sensitive administrative functions. Exploitation of this vulnerability enables attackers to list user accounts, create new administrative users, delete existing users, and modify system settings, potentially leading to a full compromise of the device.
Users are advised to implement authentication for all sensitive endpoints and enforce role-based access control. Until a patch is available, access to the vulnerable endpoint should be restricted using firewall rules, and administrative access should be limited to trusted IP addresses or through a secure VPN.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63223_Axel%20Technology%20StreamerMAX%20MK%20II%20-%20Broken%20Access%20Control | CISA-ADP | ExploitMitigationThird Party Advisory |
| https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63223_Axel%20Technology%20StreamerMAX%20MK%20II%20-%20Broken%20Access%20Control | [email protected] | ExploitMitigationThird Party Advisory |
| https://www.axeltechnology.com/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| axeltechnology streamermax mk ii firmware | >= 0.8.5, <= 1.0.3 |
CPE
Remediation
| |
| axeltechnology streamermax mk ii | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 15, 2026 | Initial Analysis | [email protected] |
| Nov 20, 2025 | CVE Modified | CISA-ADP |
| Nov 19, 2025 | New CVE Received | [email protected] |