Security Advisory

CVE-2025-53520

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-08-08 16:09:02
Last updated 2025-08-08 19:12:44
Assigner icscert
State PUBLISHED

Description

The affected product allows firmware updates to be downloaded from EG4s website, transferred via USB dongles, or installed through EG4s Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks. The TTComp archive format used for the firmware is unencrypted and can be unpacked and altered without detection.