CVE-2025-9965

Improper authentication vulnerability in Novakon P series allows unauthenticated attackers to upload and download any application from/to the device.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).
CVSS

No CVSS.

Configurations

No configuration.

History

31 Mar 2026, 13:16

Type Values Removed Values Added
References
  • () https://www.novakon.com.tw/common/frontend/download?path=/uploads/images/support/download/NOVAKON_P-Series-HMI_Security-Advisory_CVE-2025-9962-9966_Rev2_0.pdf -
  • () https://www.novakon.com.tw/en/news/detail/Security_Advisory__Firmware_Update_Available_for_NOVAKON_P_Series_HMI_Products -
Summary
  • (es) Vulnerabilidad de autenticación impropia en la serie P de Novakon permite a atacantes no autenticados cargar y descargar cualquier aplicación desde/hacia el dispositivo. Este problema afecta a la serie P: P – V2001.A.C518o2.
Summary (en) Improper authentication vulnerability in Novakon P series allows unauthenticated attackers to upload and download any application from/to the device.This issue affects P series: P – V2001.A.C518o2. (en) Improper authentication vulnerability in Novakon P series allows unauthenticated attackers to upload and download any application from/to the device.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).

03 Nov 2025, 19:16

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Sep/70 -

23 Sep 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-23 12:15

Updated : 2026-06-17 10:10


NVD link : CVE-2025-9965

Mitre link : CVE-2025-9965

CVE.ORG link : CVE-2025-9965


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication