S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated May 31, 2025

CVE-2025-0674 Scanner

CVE-2025-0674 Scanner - Unauthorized Admin Access vulnerability in Elber ESE DVB-S/S2

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.3k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-0674
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the password management functionality. Attackers can exploit this issue by manipulating the endpoint to overwrite any user's password within the system. This grants them unauthorized administrative access to protected areas of the application, compromising the device's system security.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Signum DVB-S/S2 IRDby Elber
0
Cleber/3 Broadcast Multi-Purpose Platformby Elber
1.0
Reble610 M/ODU XPIC IP-ASI-SDHby Elber
0.01
ESE DVB-S/S2 Satellite Receiverby Elber
0
Updated Aug 22, 2026View on NVD →
Detail

Elber ESE DVB-S/S2 is a satellite equipment product employed by companies for broadcast and communication solutions, supporting a range of satellite modulation standards for various professional applications. It is widely used by broadcasters and service providers for signal reception and transmission. The product includes management interfaces accessible via network connections to configure and oversee device settings. Users leverage the DVB-S/S2 standards to transmit audio and video data efficiently across large geographical areas. The software enables users to perform diverse tasks including channel reception, decryption, and re-encoding services. Elber products are a crucial component in the chain for ensuring uninterrupted satellite broadcast services.

The vulnerability identified within Elber ESE DVB-S/S2 pertains to an authentication bypass flaw. It allows attackers to exploit access controls, potentially enabling unauthorized users to access sensitive areas of the application. By circumventing authentication mechanisms, unauthorized actors can change user credentials, thereby escalating privileges within the system. This security gap is critical as it undermines the integrity and confidentiality of the entire setup. The exploitation requires knowledge of specific endpoint manipulation which attackers could utilize to alter administrative settings. The vulnerability could thus lead to potential system compromise.

The technical detail of the vulnerability manifests within the password management module of the system. Attackers can send crafted HTTP requests to endpoints like `/modules/pwd.html` to manipulate password settings without proper authorization. The request `GET /json_data/set_pwd?lev=2&pass=admin1234` indicates a misuse where control over the password system is gained. Access to these endpoints is not adequately protected against unauthorized access attempts. The flaw lies in the inadequate authentication checks at critical stages of password management interactions. These endpoints allow parameter alteration, providing attackers a pathway to gain control over system-level access.

Exploiting this vulnerability could result in unauthorized administrative control, leading to potential full system access by malicious entities. It can compromise sensitive data through unauthorized password reset or alterations. There is an elevated risk of further attacks, including the deployment of malicious software or data corruption. Unchecked exploitation could disrupt operations, rendering critical satellite communications compromised. This could also lead to economic losses and reputation damage for companies relying on Elber products for their broadcast needs. In the worst scenario, attackers could manipulate broadcast signals and server operations.

REFERENCES

Solution Advice
  • Implement robust authentication mechanisms that enforce strong password policies and regular password changes.
  • Restrict access to administrative endpoints and ensure proper authorization checks are in place for each access request.
  • Regularly update Elber devices to the latest versions to incorporate security patches and improvements.
  • Perform thorough security audits to identify and rectify potential authentication bypass routes.
  • Educate personnel on security best practices and the importance of safeguarding administrative access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.