The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system compromise.
References
| Link | Resource |
|---|---|
| https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63207_RVR%20Elettronica%20TEX%20Broken%20Access%20Control | Exploit Third Party Advisory |
| https://www.rvr.it/en/ | Product |
| https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63207_RVR%20Elettronica%20TEX%20Broken%20Access%20Control | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
Configuration 10 (hide)
| AND |
|
Configuration 11 (hide)
| AND |
|
History
15 Jan 2026, 19:55
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:rvr:tex2000light_firmware:texl-000400:*:*:*:*:*:*:* cpe:2.3:h:rvr:tex2500lcd:-:*:*:*:*:*:*:* cpe:2.3:h:rvr:tex3500lcd:-:*:*:*:*:*:*:* cpe:2.3:h:rvr:tex100lcd\/s:-:*:*:*:*:*:*:* cpe:2.3:o:rvr:tex150lcd\/s_firmware:texl-000400:*:*:*:*:*:*:* cpe:2.3:o:rvr:tex50lcd\/s_firmware:texl-000400:*:*:*:*:*:*:* cpe:2.3:o:rvr:tex3500lcd_firmware:texl-000400:*:*:*:*:*:*:* cpe:2.3:h:rvr:tex2000light:-:*:*:*:*:*:*:* cpe:2.3:h:rvr:tex702lcd:-:*:*:*:*:*:*:* cpe:2.3:h:rvr:tex150lcd\/s:-:*:*:*:*:*:*:* cpe:2.3:o:rvr:tex2500lcd_firmware:texl-000400:*:*:*:*:*:*:* cpe:2.3:o:rvr:tex100lcd\/s_firmware:texl-000400:*:*:*:*:*:*:* cpe:2.3:h:rvr:tex300lcd:-:*:*:*:*:*:*:* cpe:2.3:o:rvr:tex30lcd\/s_firmware:texl-000400:*:*:*:*:*:*:* cpe:2.3:h:rvr:tex50lcd\/s:-:*:*:*:*:*:*:* cpe:2.3:o:rvr:tex300lcd_firmware:texl-000400:*:*:*:*:*:*:* cpe:2.3:h:rvr:tex30lcd\/s:-:*:*:*:*:*:*:* cpe:2.3:h:rvr:tex1002lcd:-:*:*:*:*:*:*:* cpe:2.3:o:rvr:tex702lcd_firmware:texl-000400:*:*:*:*:*:*:* cpe:2.3:h:rvr:tex502lcd:-:*:*:*:*:*:*:* cpe:2.3:o:rvr:tex502lcd_firmware:texl-000400:*:*:*:*:*:*:* cpe:2.3:o:rvr:tex1002lcd_firmware:texl-000400:*:*:*:*:*:*:* |
|
| References | () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63207_RVR%20Elettronica%20TEX%20Broken%20Access%20Control - Exploit, Third Party Advisory | |
| References | () https://www.rvr.it/en/ - Product | |
| First Time |
Rvr tex3500lcd Firmware
Rvr tex50lcd\/s Rvr tex300lcd Firmware Rvr tex50lcd\/s Firmware Rvr tex300lcd Rvr tex2000light Firmware Rvr tex1002lcd Firmware Rvr tex2000light Rvr tex702lcd Rvr tex502lcd Rvr tex2500lcd Firmware Rvr tex30lcd\/s Rvr tex3500lcd Rvr tex150lcd\/s Rvr tex702lcd Firmware Rvr tex100lcd\/s Firmware Rvr tex502lcd Firmware Rvr tex2500lcd Rvr tex150lcd\/s Firmware Rvr Rvr tex30lcd\/s Firmware Rvr tex1002lcd Rvr tex100lcd\/s |
20 Nov 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-287 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| References | () https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-63207_RVR%20Elettronica%20TEX%20Broken%20Access%20Control - |
19 Nov 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-19 18:15
Updated : 2026-01-15 19:55
NVD link : CVE-2025-63207
Mitre link : CVE-2025-63207
CVE.ORG link : CVE-2025-63207
JSON object : View
Products Affected
rvr
- tex300lcd
- tex3500lcd
- tex502lcd_firmware
- tex100lcd\/s
- tex2500lcd
- tex100lcd\/s_firmware
- tex50lcd\/s_firmware
- tex1002lcd
- tex2500lcd_firmware
- tex1002lcd_firmware
- tex300lcd_firmware
- tex3500lcd_firmware
- tex30lcd\/s_firmware
- tex50lcd\/s
- tex30lcd\/s
- tex150lcd\/s
- tex502lcd
- tex150lcd\/s_firmware
- tex702lcd_firmware
- tex702lcd
- tex2000light_firmware
- tex2000light
CWE
CWE-287
Improper Authentication
