CVE-2025-29270CRITICAL 10.0EPSS p21.0%
CVE-2025-29270CVE-2025-29270
Description
Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the admin panel and complete control of the device.
Scoring
| CVSS 3.1 | 10.0 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 0.29% probability of exploitation · percentile 21.0% · 2026-06-18T12:00:27Z |
| Published | 2025-10-31 |
| Last modified | 2026-04-15 |
Underlying weaknesses· 2
References
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Exposure of Sensitive Information to an Unauthorized Actorcwe-200 | 0% | live |
| Weakness | Improper Access Controlcwe-284 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.