{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-14T09:09:34.998","vulnerabilities":[{"cve":{"id":"CVE-2025-27803","sourceIdentifier":"551230f0-3615-47bd-b7cc-93e92e730bbf","published":"2025-05-21T12:16:21.100","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately gets administrative access to the devices and can perform arbitrary administrative actions and reconfigure the devices or potentially gain access to sensitive data."},{"lang":"es","value":"Los dispositivos no implementan ninguna autenticación para la interfaz web ni para el servidor MQTT. Un atacante con acceso de red al dispositivo obtiene inmediatamente acceso administrativo y puede realizar acciones administrativas arbitrarias, reconfigurarlos o, potencialmente, acceder a datos confidenciales."}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":4.2}]},"weaknesses":[{"source":"551230f0-3615-47bd-b7cc-93e92e730bbf","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://r.sec-consult.com/echarge","source":"551230f0-3615-47bd-b7cc-93e92e730bbf"},{"url":"http://seclists.org/fulldisclosure/2025/May/23","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}