Missing Authentication for Critical Function in Radiometrics VizAir
Vulnerability Description
Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access and API requests. Attackers can modify configurations without authentication, potentially manipulating active runway settings and misleading air traffic control (ATC) and pilots. Additionally, manipulated meteorological data could mislead forecasters and ATC, causing inaccurate flight planning.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-61956
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Souvik Kandar
References
Affected Vendor
Radiometrics
View all reports →