CVE 7.3 HIGH

Daikin Security Gateway Weak Password Recovery Mechanism for Forgotten Password_CVE-2025-10127

7.3 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Description

Daikin Security Gateway is vulnerable to an authorization bypass through
a user-controlled key vulnerability that could allow an attacker to
bypass authentication. An unauthorized attacker could access the system
without prior credentials.

Basic Information

ID CVE-2025-10127
Source icscert
Published Sep 11, 2025 at 19:44
Modified Sep 11, 2025 at 20:23

Affected Product

Vendor Daikin
Product Security Gateway
Version App: 100, Frm: 214
Affected Versions Daikin Security Gateway App: 100, Frm: 214

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.