---
id: CVE-2025-9964
title: No password for the root user is set in Novakon P series
summary: >-
  No password for the root user is set in Novakon P series. This allows phyiscal
  attackers to enter the console easily. 

  This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build
                        2026.02.06 (commit d0f97fd9).
severity: none
cwe:
  - CWE-521
published: '2025-09-23'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9964'
references:
  - url: >-
      https://cyberdanube.com/security-research/multiple-vulnerabilities-in-novakon-hmi-series/
    label: office@cyberdanube.com
  - url: >-
      https://www.novakon.com.tw/common/frontend/download?path=/uploads/images/support/download/NOVAKON_P-Series-HMI_Security-Advisory_CVE-2025-9962-9966_Rev2_0.pdf
    label: office@cyberdanube.com
  - url: >-
      https://www.novakon.com.tw/en/news/detail/Security_Advisory__Firmware_Update_Available_for_NOVAKON_P_Series_HMI_Products
    label: office@cyberdanube.com
  - url: 'http://seclists.org/fulldisclosure/2025/Sep/70'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00217
epssPercentile: 0.10796
ingestedAt: '2026-09-26T00:22:39.947Z'
---

## Overview

No password for the root user is set in Novakon P series. This allows phyiscal attackers to enter the console easily. 
This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build
                      2026.02.06 (commit d0f97fd9).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
