CVE-2025-36535CRITICAL 10.0EPSS p57.3%
CVE-2025-36535CVE-2025-36535
Description
The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead to configuration changes, operational disruption, or arbitrary code execution depending on the environment and exposed functionality.
Scoring
| CVSS 3.1 | 10.0 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 0.97% probability of exploitation · percentile 57.3% · 2026-06-19T12:03:05Z |
| Published | 2025-05-21 |
| Last modified | 2026-04-15 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Missing Authentication for Critical Functioncwe-306 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.