CVE-2025-45583

CRITICAL

Audi Universal Traffic Recorder 2.0 - Improper Authentication via FTP

Title source: llm
STIX 2.1

Description

Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the service using any combination of username and password.

References (1)

Core 1

Scores

CVSS v3 9.1
EPSS 0.0034
EPSS Percentile 25.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
audi/universal_traffic_recorder_firmware 1.52
Published Sep 12, 2025
Tracked Since Feb 18, 2026