CVE-2025-28232

CRITICAL

Jmbroadcast Jmb0150 Firmware - Improper Access Control

Title source: rule
STIX 2.1

Description

Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without authentication.

Scores

CVSS v3 9.1
EPSS 0.0019
EPSS Percentile 40.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
jmbroadcast/jmb0150_firmware 1.0
Published Apr 18, 2025
Tracked Since Feb 18, 2026