CRITICAL · 9.8

CVE-2025-57441

The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Telnet service on port 9990. Upon connection, the attacker can access a protocol p...

Vulnerability Description

The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Telnet service on port 9990. Upon connection, the attacker can access a protocol preamble that leaks the video mode, routing configuration, input/output labels, device model, and even internal identifiers such as the unique ID. This can be used for reconnaissance and planning further attacks.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
BlackmagicdesignAtem Mini Pro Firmware2.7
BlackmagicdesignAtem Mini Pro-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-57441?

CVE-2025-57441 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Telnet service on port 9990. Upon connection, the attacker can access a protocol p...

How severe is CVE-2025-57441?

CVE-2025-57441 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2025-57441?

Check the references section above for vendor advisories and patch information. Affected products include: Blackmagicdesign Atem Mini Pro Firmware, Blackmagicdesign Atem Mini Pro.