CVE-2025-62775High· 8.0▾ TwilightMercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Mercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62292Medium· 4.3In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including the email addresse…
CVE-2026-106553Low· 2.2In sshd in OpenSSH before 10.6, credentials can incorrectly persist after failure of a GSSAPIAuthentication authentication attempt.
CVE-2026-106555Low· 2.2In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts.
CVE-2024-31573Medium· 4.0XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.
GHSA-hmpr-c9rf-qcrfHigh· 6.8Duplicate Advisory: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
CVE-2025-59453Low· 3.2Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access