CVE-2025-15017 - CVE House
Back to Database
Status published High CVE-2025-15017

A vulnerability exists in serial device servers where active debug...

Vulnerability Description

A vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with physical access to the device can directly connect to the UART interface and, without authentication, user interaction, or execution conditions, gain unauthorized access to internal debug functionality. Exploitation is low complexity and allows an attacker to execute privileged operations and access sensitive system resources, resulting in a high impact to the confidentiality, integrity, and availability of the affected device. No security impact to external or dependent systems has been identified.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-15017

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

NPort 5000AI-M12 Series, NPort 5100 Series, NPort 5100A Series, NPort 5200 Series, NPort 5200A Series, NPort 5400 Series, NPort 5600 Series, NPort 5600-DT Series, NPort IA5000 Series, NPort IA5000A Series, NPort IA5000-G2 Series
Vulnerable Versions:
1.0

Timeline

Official Publish: December 31st, 2025
Last Modified: December 31st, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.