A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver
version drv_gen5_106-01-2380, allows
malformed packets to be sent through BACnet MS/TP network causing the devices to enter a fault state. This fault state requires a manual power cycle to
return the device to network visibility.
Advisories

No advisories yet.

Fixes

Solution

These vulnerabilities have been remediated in cumulative releases for versions 8.5, 9.0, and Gen5 driver version drv_gen5_108-04-20120 or later.  Support for versions 8.0, 7.0,6.5, 6.1, 6.0 has expired.


Workaround

No workaround given by the vendor.

History

Fri, 28 Nov 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Carrier
Carrier automatedlogic Webctrl
Carrier i-vu
Vendors & Products Carrier
Carrier automatedlogic Webctrl
Carrier i-vu

Thu, 27 Nov 2025 01:15:00 +0000

Type Values Removed Values Added
Description A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver version drv_gen5_106-01-2380, allows malformed packets to be sent through BACnet MS/TP network causing the devices to enter a fault state. This fault state requires a manual power cycle to return the device to network visibility.
Title ALC WebCTRL Carrier i-Vu and Gen5 Controllers Array Index out-of-range
Weaknesses CWE-129
CWE-248
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Carrier

Published:

Updated: 2025-11-28T19:34:27.510Z

Reserved: 2025-01-22T20:22:14.084Z

Link: CVE-2025-0657

cve-icon Vulnrichment

Updated: 2025-11-28T14:41:25.049Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-27T01:15:46.437

Modified: 2025-12-01T15:39:33.110

Link: CVE-2025-0657

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-27T16:25:57Z