A vulnerability, which was classified as problematic, has been found in FNKvision FNK-GU2 up to 40.1.7. Affected by this issue is some unknown functionality of the file /rom/wpa_supplicant.conf. The manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 8e-05}

epss

{'score': 6e-05}


Wed, 09 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Jul 2025 04:30:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as problematic, has been found in FNKvision FNK-GU2 up to 40.1.7. Affected by this issue is some unknown functionality of the file /rom/wpa_supplicant.conf. The manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
Title FNKvision FNK-GU2 wpa_supplicant.conf cleartext storage
Weaknesses CWE-310
CWE-312
References
Metrics cvssV2_0

{'score': 0.8, 'vector': 'AV:L/AC:H/Au:M/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 1.6, 'vector': 'CVSS:3.0/AV:P/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 1.6, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 1, 'vector': 'CVSS:4.0/AV:P/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-07-09T04:02:05.353Z

Updated: 2025-07-09T14:17:36.350Z

Reserved: 2025-07-07T13:19:21.130Z

Link: CVE-2025-7215

cve-icon Vulnrichment

Updated: 2025-07-09T14:17:32.291Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-09T05:15:39.123

Modified: 2025-07-10T13:18:53.830

Link: CVE-2025-7215

cve-icon Redhat

No data.