Security Gateway is vulnerable to an authorization bypass through
a user-controlled key vulnerability that could allow an attacker to
bypass authentication. An unauthorized attacker could access the system
without prior credentials.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28991 | Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials. |
Solution
No solution given by the vendor.
Workaround
Daikin Europe N.V has reported they will not fix this vulnerability and will respond directly to user inquiries. For more information, contact Daikin customer support https://www.daikin.eu/en_us/customers/support.html .
Wed, 24 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Thu, 18 Sep 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Daikin Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials. | Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials. |
| Title | Daikin Security Gateway Weak Password Recovery Mechanism for Forgotten Password | Daikin Europe N.V Security Gateway Weak Password Recovery Mechanism for Forgotten Password |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 12 Sep 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Daikin
Daikin security Gateway |
|
| Vendors & Products |
Daikin
Daikin security Gateway |
Thu, 11 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Sep 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Daikin Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerability that could allow an attacker to bypass authentication. An unauthorized attacker could access the system without prior credentials. | |
| Title | Daikin Security Gateway Weak Password Recovery Mechanism for Forgotten Password | |
| Weaknesses | CWE-640 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-09-24T13:36:09.876Z
Reserved: 2025-09-08T19:04:34.440Z
Link: CVE-2025-10127
Updated: 2025-09-11T20:23:10.392Z
Status : Awaiting Analysis
Published: 2025-09-11T20:15:33.667
Modified: 2025-09-18T14:15:45.777
Link: CVE-2025-10127
No data.
OpenCVE Enrichment
Updated: 2025-09-12T09:11:15Z
EUVD