CRITICAL · 9.8

CVE-2025-57432

Blackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This service allows remote attackers to manipulate stream settings, including changing...

Vulnerability Description

Blackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This service allows remote attackers to manipulate stream settings, including changing video modes and possibly altering device functionality. No credentials or authentication mechanisms are required to interact with the Telnet interface.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
BlackmagicdesignWeb Presenter Hd Firmware3.3
BlackmagicdesignWeb Presenter Hd-
BlackmagicdesignWeb Presenter 4K Firmware3.3
BlackmagicdesignWeb Presenter 4K-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-57432?

CVE-2025-57432 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Blackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This service allows remote attackers to manipulate stream settings, including changing...

How severe is CVE-2025-57432?

CVE-2025-57432 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2025-57432?

Check the references section above for vendor advisories and patch information. Affected products include: Blackmagicdesign Web Presenter Hd Firmware, Blackmagicdesign Web Presenter Hd, Blackmagicdesign Web Presenter 4K Firmware, Blackmagicdesign Web Presenter 4K.