peter bassill · operator
$ cve CVE-2025-65212 JSON

CVE-2025-65212

9.8
CRITICAL · CVSS 3.1 · EPSS 5.4% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the device's insufficient cookie verification, allowing an attacker to directly request the configuration file address and download the core configuration file without logging into the device management backend. By reading the corresponding username and self-decrypted MD5 password in the core configuration file, the attacker can directly log in to the backend, thereby bypassing the front-end backend login page.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.36% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-565
On CISA KEVno
Public exploitnone known
Published2026-01-06
Last modified2026-06-17

Affected (2)

VendorProduct
njhysthy511
njhysthy511 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD