Vulnerability Description
The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system compromise.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rvr | Tex30Lcd\/S Firmware | texl-000400 |
| Rvr | Tex30Lcd\/S | - |
| Rvr | Tex50Lcd\/S Firmware | texl-000400 |
| Rvr | Tex50Lcd\/S | - |
| Rvr | Tex100Lcd\/S Firmware | texl-000400 |
| Rvr | Tex100Lcd\/S | - |
| Rvr | Tex150Lcd\/S Firmware | texl-000400 |
| Rvr | Tex150Lcd\/S | - |
| Rvr | Tex300Lcd Firmware | texl-000400 |
| Rvr | Tex300Lcd | - |
| Rvr | Tex502Lcd Firmware | texl-000400 |
| Rvr | Tex502Lcd | - |
| Rvr | Tex702Lcd Firmware | texl-000400 |
| Rvr | Tex702Lcd | - |
| Rvr | Tex3500Lcd Firmware | texl-000400 |
| Rvr | Tex3500Lcd | - |
| Rvr | Tex1002Lcd Firmware | texl-000400 |
| Rvr | Tex1002Lcd | - |
| Rvr | Tex2000Light Firmware | texl-000400 |
| Rvr | Tex2000Light | - |
Related Weaknesses (CWE)
References
- https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-6320ExploitThird Party Advisory
- https://www.rvr.it/en/Product
- https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-6320ExploitThird Party Advisory
FAQ
What is CVE-2025-63207?
CVE-2025-63207 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker ca...
How severe is CVE-2025-63207?
CVE-2025-63207 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-63207?
Check the references section above for vendor advisories and patch information. Affected products include: Rvr Tex30Lcd\/S Firmware, Rvr Tex30Lcd\/S, Rvr Tex50Lcd\/S Firmware, Rvr Tex50Lcd\/S, Rvr Tex100Lcd\/S Firmware.