the device identifier, which is a numerical identifier no more than 10
digits. A malicious actor can enumerate potential targets by
incrementing or decrementing from known identifiers or through
enumerating random digit sequences.
No analysis available yet.
Vendor Workaround
SinoTrack did not respond to CISA's request for coordination. Please contact SinoTrack https://www.sinotrackgps.com/help-center for more information.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18211 | User names used to access the web management interface are limited to the device identifier, which is a numerical identifier no more than 10 digits. A malicious actor can enumerate potential targets by incrementing or decrementing from known identifiers or through enumerating random digit sequences. |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 12 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | User names used to access the web management interface are limited to the device identifier, which is a numerical identifier no more than 10 digits. A malicious actor can enumerate potential targets by incrementing or decrementing from known identifiers or through enumerating random digit sequences. | |
| Title | SinoTrack GPS Receiver Weak Authentication | |
| Weaknesses | CWE-204 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-06-12T20:14:57.139Z
Reserved: 2025-06-02T20:33:03.000Z
Link: CVE-2025-5485
Updated: 2025-06-12T20:14:49.917Z
Status : Awaiting Analysis
Published: 2025-06-12T20:15:22.283
Modified: 2025-06-16T12:32:18.840
Link: CVE-2025-5485
No data.
OpenCVE Enrichment
No data.
EUVD