Vulnerability Description
Blackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This service allows remote attackers to manipulate stream settings, including changing video modes and possibly altering device functionality. No credentials or authentication mechanisms are required to interact with the Telnet interface.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Blackmagicdesign | Web Presenter Hd Firmware | 3.3 |
| Blackmagicdesign | Web Presenter Hd | - |
| Blackmagicdesign | Web Presenter 4K Firmware | 3.3 |
| Blackmagicdesign | Web Presenter 4K | - |
Related Weaknesses (CWE)
References
- https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-5743ExploitThird Party Advisory
- https://www.blackmagicdesign.com/Product
- https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-5743ExploitThird Party Advisory
FAQ
What is CVE-2025-57432?
CVE-2025-57432 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Blackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This service allows remote attackers to manipulate stream settings, including changing...
How severe is CVE-2025-57432?
CVE-2025-57432 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-57432?
Check the references section above for vendor advisories and patch information. Affected products include: Blackmagicdesign Web Presenter Hd Firmware, Blackmagicdesign Web Presenter Hd, Blackmagicdesign Web Presenter 4K Firmware, Blackmagicdesign Web Presenter 4K.