CVE-2025-9964

No password for the root user is set in Novakon P series. This allows phyiscal attackers to enter the console easily. This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).
CVSS

No CVSS.

Configurations

No configuration.

History

31 Mar 2026, 13:16

Type Values Removed Values Added
Summary (en) No password for the root user is set in Novakon P series. This allows phyiscal attackers to enter the console easily. This issue affects P series: P – V2001.A.C518o2. (en) No password for the root user is set in Novakon P series. This allows phyiscal attackers to enter the console easily. This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).
References
  • () https://www.novakon.com.tw/common/frontend/download?path=/uploads/images/support/download/NOVAKON_P-Series-HMI_Security-Advisory_CVE-2025-9962-9966_Rev2_0.pdf -
  • () https://www.novakon.com.tw/en/news/detail/Security_Advisory__Firmware_Update_Available_for_NOVAKON_P_Series_HMI_Products -

03 Nov 2025, 19:16

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Sep/70 -

23 Sep 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-23 12:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-9964

Mitre link : CVE-2025-9964

CVE.ORG link : CVE-2025-9964


JSON object : View

Products Affected

No product.

CWE
CWE-521

Weak Password Requirements