a user-controlled key vulnerability that could allow an attacker to
bypass authentication. An unauthorized attacker could access the system
without prior credentials.
Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
Daikin has reported they will not fix this vulnerability and will respond directly to user inquiries. For more information, contact Daikin customer support https://www.daikin.eu/en_us/customers/support.html .
Thu, 11 Sep 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 11 Sep 2025 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Daikin Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials. | |
Title | Daikin Security Gateway Weak Password Recovery Mechanism for Forgotten Password | |
Weaknesses | CWE-640 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-09-11T20:23:12.849Z
Reserved: 2025-09-08T19:04:34.440Z
Link: CVE-2025-10127

Updated: 2025-09-11T20:23:10.392Z

Status : Received
Published: 2025-09-11T20:15:33.667
Modified: 2025-09-11T20:15:33.667
Link: CVE-2025-10127

No data.

No data.