CVE-2025-57441

CRITICAL

Blackmagic ATEM Mini Pro 2.7 - Unauthenticated Sensitive Information Exposure via Telnet Port 9990

Title source: llm
STIX 2.1

Description

The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Telnet service on port 9990. Upon connection, the attacker can access a protocol preamble that leaks the video mode, routing configuration, input/output labels, device model, and even internal identifiers such as the unique ID. This can be used for reconnaissance and planning further attacks.

Scores

CVSS v3 9.8
EPSS 0.0051
EPSS Percentile 39.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-200
Status published
Products (1)
blackmagicdesign/atem_mini_pro_firmware 2.7
Published Sep 22, 2025
Tracked Since Feb 18, 2026