CVE-2025-27853

HIGH

Garmin WDU v1 1.4.6 & v2 5.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU web site only performs authentication with the client within the client's browser. The WebSockets used to communicate with the WDU server do not enforce any authentication. An attacker may bypass all authentication mechanisms by directly utilizing the remote APIs available on the websocket.

Scores

CVSS v3 7.3
EPSS 0.0030
EPSS Percentile 21.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (2)
garmin/empirbus_wireless_display_unit_firmware 1.4.6
garmin/empirbus_wireless_display_unit_firmware 5.00
Published May 13, 2026
Tracked Since May 14, 2026