CVE-2025-46414

The affected product does not limit the number of attempts for inputting
 the correct PIN for a registered product, which may allow an attacker 
to gain unauthorized access using brute-force methods if they possess a 
valid device serial number. The API provides clear feedback when the 
correct PIN is entered. This vulnerability was patched in a server-side 
update on April 6, 2025.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
icscertCNA
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---