CVE 7.4 HIGH

Simplcity Device Manager exposes NTLMv2 hash_CVE-2025-10285

7.4 / 10
HIGH
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

The web interface of the Silicon Labs Simplicity Device Manager is exposed publicly and can be used to extract the NTLMv2 hash which an attacker could use to crack the user's domain password.

Basic Information

ID CVE-2025-10285
Source Silabs
Published Dec 4, 2025 at 21:36

Affected Product

Vendor silabs.com
Product Simplicity Studio V6
Affected Versions silabs.com Simplicity Studio V6 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.