CVE-2025-63207

The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system compromise.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:rvr:tex30lcd\/s_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex30lcd\/s:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:rvr:tex50lcd\/s_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex50lcd\/s:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:rvr:tex100lcd\/s_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex100lcd\/s:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:rvr:tex150lcd\/s_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex150lcd\/s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:rvr:tex300lcd_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex300lcd:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:rvr:tex502lcd_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex502lcd:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:rvr:tex702lcd_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex702lcd:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:rvr:tex3500lcd_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex3500lcd:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:rvr:tex1002lcd_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex1002lcd:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:rvr:tex2000light_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex2000light:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:rvr:tex2500lcd_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex2500lcd:-:*:*:*:*:*:*:*

History

15 Jan 2026, 19:55

Type Values Removed Values Added
References () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63207_RVR%20Elettronica%20TEX%20Broken%20Access%20Control - () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63207_RVR%20Elettronica%20TEX%20Broken%20Access%20Control - Exploit, Third Party Advisory
References () https://www.rvr.it/en/ - () https://www.rvr.it/en/ - Product
First Time Rvr tex3500lcd Firmware
Rvr tex50lcd\/s
Rvr tex300lcd Firmware
Rvr tex50lcd\/s Firmware
Rvr tex300lcd
Rvr tex2000light Firmware
Rvr tex1002lcd Firmware
Rvr tex2000light
Rvr tex702lcd
Rvr tex502lcd
Rvr tex2500lcd Firmware
Rvr tex30lcd\/s
Rvr tex3500lcd
Rvr tex150lcd\/s
Rvr tex702lcd Firmware
Rvr tex100lcd\/s Firmware
Rvr tex502lcd Firmware
Rvr tex2500lcd
Rvr tex150lcd\/s Firmware
Rvr
Rvr tex30lcd\/s Firmware
Rvr tex1002lcd
Rvr tex100lcd\/s
CPE cpe:2.3:o:rvr:tex2000light_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex2500lcd:-:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex3500lcd:-:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex100lcd\/s:-:*:*:*:*:*:*:*
cpe:2.3:o:rvr:tex150lcd\/s_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:o:rvr:tex50lcd\/s_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:o:rvr:tex3500lcd_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex2000light:-:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex702lcd:-:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex150lcd\/s:-:*:*:*:*:*:*:*
cpe:2.3:o:rvr:tex2500lcd_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:o:rvr:tex100lcd\/s_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex300lcd:-:*:*:*:*:*:*:*
cpe:2.3:o:rvr:tex30lcd\/s_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex50lcd\/s:-:*:*:*:*:*:*:*
cpe:2.3:o:rvr:tex300lcd_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex30lcd\/s:-:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex1002lcd:-:*:*:*:*:*:*:*
cpe:2.3:o:rvr:tex702lcd_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:h:rvr:tex502lcd:-:*:*:*:*:*:*:*
cpe:2.3:o:rvr:tex502lcd_firmware:texl-000400:*:*:*:*:*:*:*
cpe:2.3:o:rvr:tex1002lcd_firmware:texl-000400:*:*:*:*:*:*:*

20 Nov 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63207_RVR%20Elettronica%20TEX%20Broken%20Access%20Control - () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63207_RVR%20Elettronica%20TEX%20Broken%20Access%20Control -
CWE CWE-287

19 Nov 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-19 18:15

Updated : 2026-01-15 19:55


NVD link : CVE-2025-63207

Mitre link : CVE-2025-63207

CVE.ORG link : CVE-2025-63207


JSON object : View

Products Affected

rvr

  • tex300lcd
  • tex3500lcd
  • tex502lcd_firmware
  • tex100lcd\/s
  • tex2500lcd
  • tex100lcd\/s_firmware
  • tex50lcd\/s_firmware
  • tex1002lcd
  • tex2500lcd_firmware
  • tex1002lcd_firmware
  • tex300lcd_firmware
  • tex3500lcd_firmware
  • tex30lcd\/s_firmware
  • tex50lcd\/s
  • tex30lcd\/s
  • tex150lcd\/s
  • tex502lcd
  • tex150lcd\/s_firmware
  • tex702lcd_firmware
  • tex702lcd
  • tex2000light_firmware
  • tex2000light
CWE
CWE-287

Improper Authentication