CVE-2025-6763 - CVE House
Back to Database
Status published Critical CVE-2025-6763

Comet System H3531 Web-based Management setupA.cfg missing authentication

Vulnerability Description

A vulnerability was found in Comet System T0510, T3510, T3511, T4511, T6640, T7511, T7611, P8510, P8552 and H3531 1.60. Affected by this issue is some unknown functionality of the file /setupA.cfg of the component Web-based Management Interface. Performing manipulation results in missing authentication. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The exploit has been made public and could be used. There are still doubts about whether this vulnerability truly exists. The vendor explains, that "[d]evices described at CVE are not intended to be exposed into internet and proper security of devices is to end-users."

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-6763

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • zeke (VulDB User)

Affected Vendor

Comet System

View all reports →

Affected Software

T0510, T3510, T3511, T4511, T6640, T7511, T7611, P8510, P8552, H3531
Vulnerable Versions:
1.60

Timeline

Official Publish: June 27th, 2025
Last Modified: October 8th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:W/RC:C

Weaknesses (CWE)