CVE-2026-10825EPSS p13.7%

CVE-2026-10825CVE-2026-10825

Description

A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests. A low-privileged authenticated attacker can send a specially crafted request that causes service disruption and may result in an unexpected device reboot.

Scoring

EPSS0.24% probability of exploitation · percentile 13.7% · 2026-10-05T12:00:23Z
Last modified2026-06-16
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.