CVE-2025-9964 - CVE House
Back to Database
Status published High CVE-2025-9964

Weak Authentication for Root User

Vulnerability Description

No password for the root user is set in Novakon P series. This allows phyiscal attackers to enter the console easily. This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9964

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • S. Dietz (CyberDanube)

Affected Vendor

Affected Software

P series (P07, P10, P12, P15)
Vulnerable Versions:
P – V2001.A.c518o2

Timeline

Official Publish: September 23rd, 2025
Last Modified: March 31st, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.