CVE-2025-57437

CRITICAL

Blackmagic Web Presenter HD Firmware 3.3 - Unauthenticated Sensitive Information Exposure via Telnet Service

Title source: llm
STIX 2.1

Description

The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected, the service reveals extensive device configuration data including: - Model, version, and unique identifiers - Network settings including IP, MAC, DNS - Current stream platform, stream key, and streaming URL - Audio/video configuration This data can be used to hijack live streams or perform network reconnaissance.

Scores

CVSS v3 9.8
EPSS 0.0049
EPSS Percentile 38.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-200
Status published
Products (1)
blackmagicdesign/web_presenter_hd_firmware 3.3
Published Sep 22, 2025
Tracked Since Feb 18, 2026