Vulnerability Description
The affected product does not limit the number of attempts for inputting the correct PIN for a registered product, which may allow an attacker to gain unauthorized access using brute-force methods if they possess a valid device serial number. The API provides clear feedback when the correct PIN is entered. This vulnerability was patched in a server-side update on April 6, 2025.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-46414?
CVE-2025-46414 is a vulnerability with a CVSS score of 8.1 (HIGH). The affected product does not limit the number of attempts for inputting the correct PIN for a registered product, which may allow an attacker to gain unauthorized access using brute-force methods i...
How severe is CVE-2025-46414?
CVE-2025-46414 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-46414?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.