Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access and API requests. Attackers can modify configurations without authentication, potentially manipulating active runway settings and misleading air traffic control (ATC) and pilots. Additionally, manipulated meteorological data could mislead forecasters and ATC, causing inaccurate flight planning.
History

Wed, 05 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Radiometrics
Radiometrics vizair
Vendors & Products Radiometrics
Radiometrics vizair

Tue, 04 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
Description Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access and API requests. Attackers can modify configurations without authentication, potentially manipulating active runway settings and misleading air traffic control (ATC) and pilots. Additionally, manipulated meteorological data could mislead forecasters and ATC, causing inaccurate flight planning.
Title Missing Authentication for Critical Function in Radiometrics VizAir
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2025-11-04T16:15:05.012Z

Updated: 2025-11-04T16:26:27.186Z

Reserved: 2025-10-07T19:42:54.189Z

Link: CVE-2025-61956

cve-icon Vulnrichment

Updated: 2025-11-04T16:26:08.366Z

cve-icon NVD

Status : Received

Published: 2025-11-04T17:16:23.490

Modified: 2025-11-04T17:16:23.490

Link: CVE-2025-61956

cve-icon Redhat

No data.