The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected, the service reveals extensive device configuration data including: - Model, version, and unique identifiers - Network settings including IP, MAC, DNS - Current stream platform, stream key, and streaming URL - Audio/video configuration This data can be used to hijack live streams or perform network reconnaissance.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Blackmagicdesign
Blackmagicdesign web Presenter Hd Blackmagicdesign web Presenter Hd Firmware |
|
| CPEs | cpe:2.3:h:blackmagicdesign:web_presenter_hd:-:*:*:*:*:*:*:* cpe:2.3:o:blackmagicdesign:web_presenter_hd_firmware:3.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Blackmagicdesign
Blackmagicdesign web Presenter Hd Blackmagicdesign web Presenter Hd Firmware |
Tue, 23 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Blackmagic
Blackmagic web Presenter Hd |
|
| Vendors & Products |
Blackmagic
Blackmagic web Presenter Hd |
Mon, 22 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 | |
| Metrics |
cvssV3_1
|
Mon, 22 Sep 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected, the service reveals extensive device configuration data including: - Model, version, and unique identifiers - Network settings including IP, MAC, DNS - Current stream platform, stream key, and streaming URL - Audio/video configuration This data can be used to hijack live streams or perform network reconnaissance. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-09-22T00:00:00.000Z
Updated: 2025-09-22T17:49:40.482Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-57437
Updated: 2025-09-22T17:49:18.309Z
Status : Analyzed
Published: 2025-09-22T18:15:45.153
Modified: 2025-10-10T21:03:59.970
Link: CVE-2025-57437
No data.