CVE-2025-54816

EUVD-2026-4500
This vulnerability occurs when a WebSocket endpoint does not enforce 
proper authentication mechanisms, allowing unauthorized users to 
establish connections. As a result, attackers can exploit this weakness 
to gain unauthorized access to sensitive data or perform unauthorized 
actions. Given that no authentication is required, this can lead to 
privilege escalation and potentially compromise the security of the 
entire system.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.4 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
icscertCNA
9.4 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L