CVE-2025-1880

CVSS 3.1 Score 4.3 of 10 (medium)

Attack Complexity low
Confidentiality low
Integrity none
Availability none
Scope unchanged
Privileges Required none

Details

Published Mar 3, 2025
Updated: Mar 5, 2025
CWE ID 305
CWE ID 287

Summary

CVE-2025-1880 is a recently disclosed vulnerability affecting i-Drive i11 and i12 versions up to 20250227. This issue lies within the Device Pairing component and is classified as problematic. An attacker can exploit this vulnerability by manipulating an unknown function, resulting in an authentication bypass. Physical access to the device is required to launch the attack, and the complexity is considered high. The exploitability of this vulnerability is reported as difficult, and it remains unclear who currently maintains the product. Given that it must be assumed to be end-of-life, it is crucial for users to take immediate steps to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share