{"id":"CVE-2025-51643","title":"Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protection","summary":"Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protection. An attacker with physical access to the device can use a standard SPI programmer to extra…","severity":"low","cvss":2.4,"cvssVector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-200"],"vendor":"meitrack","product":"t366l-g_firmware","affected":["t366l-g_firmware = t366l_y24h131v039"],"published":"2025-08-28","updated":"2026-09-26","sourceUpdated":"2026-09-26T00:10:00.127","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-51643","references":[{"url":"https://github.com/NastyCrow/CVE-2025-51643","label":"cve@mitre.org"}],"tags":["nvd","exploit-available"],"epss":0.0026,"epssPercentile":0.15858,"exploits":{"github":1,"githubRepos":["https://github.com/NastyCrow/CVE-2025-51643"],"checkedAt":"2026-09-26T00:23:14.488Z"},"exploitAvailable":true,"ingestedAt":"2026-09-26T00:22:39.887Z","slug":"CVE-2025-51643","body":"## Overview\n\nMeitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protection. An attacker with physical access to the device can use a standard SPI programmer to extract the firmware using flashrom. This results in exposure of sensitive configuration data such as APN credentials, backend server information, and network parameter\n\n## Affected\n\n- `t366l-g_firmware = t366l_y24h131v039`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":25,"depthScoreParts":{"impact":13.2,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}