Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials.
History

Wed, 24 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 18 Sep 2025 13:30:00 +0000

Type Values Removed Values Added
Description Daikin Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials. Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials.
Title Daikin Security Gateway Weak Password Recovery Mechanism for Forgotten Password Daikin Europe N.V Security Gateway Weak Password Recovery Mechanism for Forgotten Password
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 12 Sep 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Daikin
Daikin security Gateway
Vendors & Products Daikin
Daikin security Gateway

Thu, 11 Sep 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 11 Sep 2025 20:00:00 +0000

Type Values Removed Values Added
Description Daikin Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials.
Title Daikin Security Gateway Weak Password Recovery Mechanism for Forgotten Password
Weaknesses CWE-640
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2025-09-11T19:44:35.008Z

Updated: 2025-09-24T13:36:09.876Z

Reserved: 2025-09-08T19:04:34.440Z

Link: CVE-2025-10127

cve-icon Vulnrichment

Updated: 2025-09-11T20:23:10.392Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-11T20:15:33.667

Modified: 2025-09-18T14:15:45.777

Link: CVE-2025-10127

cve-icon Redhat

No data.