CVE-2025-66238 - CVE House
Back to Database
Status published High CVE-2025-66238

Sunbird DCIM dcTrack and Power IQ Authentication Bypass Using an Alternate Path or Channel

Vulnerability Description

DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appliance's virtual console could exploit these features to redirect network traffic, potentially accessing restricted services or data on the host machine.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66238

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • notnotnotveg (notnotnotveg@gmail.com) reported these vulnerabilities to CISA.

Affected Vendor

Affected Software

DCIM dcTrack, IQ
Vulnerable Versions:
0, 9.2.3, 9.2.1

Timeline

Official Publish: December 4th, 2025
Last Modified: December 5th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)