CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-5872: eGauge EG3000 Energy Monitor Setting missing authentication

5.3 CVSS

Description

A vulnerability was found in eGauge EG3000 Energy Monitor 3.6.3. It has been classified as problematic. This affects an unknown part of the component Setting Handler. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Es wurde eine Schwachstelle in eGauge EG3000 Energy Monitor 3.6.3 ausgemacht. Sie wurde als problematisch eingestuft. Hiervon betroffen ist ein unbekannter Codeblock der Komponente Setting Handler. Dank Manipulation mit unbekannten Daten kann eine missing authentication-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Der Exploit steht zur öffentlichen Verfügung.

Classification

CVE ID: CVE-2025-5872

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.3

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem Types

Missing Authentication Improper Authentication

Affected Products

Vendor: eGauge

Product: EG3000 Energy Monitor

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.06% (probability of being exploited)

EPSS Percentile: 17.69% (scored less or equal to compared to others)

EPSS Date: 2025-06-25 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-5872
https://vuldb.com/?id.311631
https://vuldb.com/?ctiid.311631
https://vuldb.com/?submit.585486
https://github.com/zeke2997/CVE_request_eGauge_Systems_LLC

Timeline