PT-2026-3943 · Nerves Hub · Nerveshub
CVE-2025-64097
·
Publicado
2026-01-22
·
Atualizado
2026-02-17
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NervesHub versions 1.0.0 through 2.2.9
Description
NervesHub is a web service for managing over-the-air (OTA) firmware updates. A weakness existed where attackers could potentially compromise user API tokens due to their predictable format. These tokens included user-identifiable components and lacked sufficient cryptographic security, making them vulnerable to guessing or enumeration. Successful exploitation could lead to unauthorized access to user accounts and API actions.
Recommendations
NervesHub versions prior to 2.3.0 should be upgraded to version 2.3.0 or later.
As a temporary mitigation, consider firewalling access to the NervesHub server.
Exploit
Correção
Use of Insufficiently Random Values
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Nerveshub