CVE-2025-9497 Details
Description
Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.
A vulnerability exists in the Microchip Time Provider 4100 GNSS GrandMaster, all versions prior to 2.5.0, due to hard-coded upgrade decryption passwords. This vulnerability allows for malicious manual software updates by extracting passwords used to decrypt the configuration file and filesystem packet. Exploitation requires access to the unit and the ability to extract the root password, which is a complex and costly endeavor.
Customers are strongly advised to upgrade to the latest firmware version, once available. Upgrades can be performed through a separate management port that should not be connected to an untrusted network. Access Control Lists (ACLs) can be used to further restrict access to trusted addresses.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.gruppotim.it/en/footer/TIM-red-team.html | Microchip Technology | Vendor AdvisoryExploit |
| https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/timeprovider-4100-hardcoded-upgrade-decryption-passwords | Microchip Technology | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | Microchip Technology |
Affected Products
| Product | Versions |
|---|---|
| microchip timeprovider 4100 firmware | < 2.5.0 |
CPE
Remediation
| |
| microchip timeprovider 4100 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 12, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | Microchip Technology |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 1, 2026 | CVE Modified | CISA-ADP |
| Mar 31, 2026 | CVE Modified | Microchip Technology |
| Mar 28, 2026 | New CVE Received | Microchip Technology |