CVE-2025-46414HIGH 8.1EPSS p24.3%

CVE-2025-46414CVE-2025-46414

Description

The affected product does not limit the number of attempts for inputting the correct PIN for a registered product, which may allow an attacker to gain unauthorized access using brute-force methods if they possess a valid device serial number. The API provides clear feedback when the correct PIN is entered. This vulnerability was patched in a server-side update on April 6, 2025.

Scoring

CVSS 3.18.1 (HIGH)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.33% probability of exploitation · percentile 24.3% · 2026-06-18T12:00:27Z
Published2025-08-08
Last modified2026-04-15

Underlying weaknesses· 1

CWE-307

References

  1. https://eg4electronics.com/contact/
  2. https://www.cisa.gov/news-events/ics-advisories/icsa-25-219-07

1

TypeTargetConfidenceTier
WeaknessImproper Restriction of Excessive Authentication Attemptscwe-3070%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-41652
CVE
CVE-2025-40805
CVE
CVE-2026-24789
CVE
CVE-2025-3090
CVE
CVE-2025-54807
CVE
CVE-2025-27595
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.