CVE Vulnerabilities

CVE-2025-59392

Authentication Bypass Using an Alternate Path or Channel

Published: Nov 06, 2025 | Modified: Nov 06, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

On Elspec G5 devices through 1.2.2.19, a person with physical access to the device can reset the Admin password by inserting a USB drive (containing a publicly documented reset string) into a USB port.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Potential Mitigations

References