CVE-2025-13954

CRITICAL

EZCast Pro II <1.17478.146 - Auth Bypass

Title source: llm
STIX 2.1

Description

Hard-coded cryptographic keys in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to the admin UI

Scores

CVSS v4 9.3
EPSS 0.0003
EPSS Percentile 9.0%
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N/AU:Y/RE:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
EZCast/EZCast Pro II 1.17478.146
Published Dec 10, 2025
Tracked Since Feb 18, 2026