Vulnerability Description
Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the service using any combination of username and password.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Audi | Universal Traffic Recorder Firmware | 1.52 |
| Audi | Universal Traffic Recorder | 2.0 |
Related Weaknesses (CWE)
References
- https://2barbie.notion.site/2024-Audi-UTR-2-0-Report-1bff0be688c680cb8795efe7873ExploitThird Party Advisory
FAQ
What is CVE-2025-45583?
CVE-2025-45583 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the service using any combination of username and password.
How severe is CVE-2025-45583?
CVE-2025-45583 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-45583?
Check the references section above for vendor advisories and patch information. Affected products include: Audi Universal Traffic Recorder Firmware, Audi Universal Traffic Recorder.