CVE-2025-28232

CRITICAL

JMBroadcast JMB0150 Firmware v1.0 - Unauthenticated Admin Panel Access via HOME.php Endpoint

Title source: llm
STIX 2.1

Description

Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without authentication.

Scores

CVSS v3 9.1
EPSS 0.0051
EPSS Percentile 39.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
jmbroadcast/jmb0150_firmware 1.0
Published Apr 18, 2025
Tracked Since Feb 18, 2026