7.4
/ 10
HIGH
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Description
The web interface of the Silicon Labs Simplicity Device Manager is exposed publicly and can be used to extract the NTLMv2 hash which an attacker could use to crack the user's domain password.
Basic Information
ID
CVE-2025-10285
Source
Silabs
Published
Dec 4, 2025 at 21:36
Affected Product
Vendor
silabs.com
Product
Simplicity Studio V6
Affected Versions
silabs.com Simplicity Studio V6 0