CVE-2025-1879

A

vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This issue affects some unknown processing of the component APK. The manipulation leads to hard-coded credentials. It is possible to launch the attack on the physical device. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.

References
Link Resource
https://github.com/geo-chen/i-Drive Third Party Advisory
https://vuldb.com/?ctiid.298193 Permissions Required
https://vuldb.com/?id.298193 Third Party Advisory
https://vuldb.com/?submit.510950 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:i-drive:i11_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:i-drive:i11:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:i-drive:i12_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:i-drive:i12:*:*:*:*:*:*:*:*

History

05 Mar 2025, 14:52

Type Values Removed Values Added
References () https://github.com/geo-chen/i-Drive - () https://github.com/geo-chen/i-Drive - Third Party Advisory
References () https://vuldb.com/?ctiid.298193 - () https://vuldb.com/?ctiid.298193 - Permissions Required
References () https://vuldb.com/?id.298193 - () https://vuldb.com/?id.298193 - Third Party Advisory
References () https://vuldb.com/?submit.510950 - () https://vuldb.com/?submit.510950 - Third Party Advisory
CPE cpe:2.3:o:i-drive:i12_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:i-drive:i11_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:i-drive:i11:*:*:*:*:*:*:*:*
cpe:2.3:h:i-drive:i12:*:*:*:*:*:*:*:*
First Time I-drive
I-drive i11
I-drive i12 Firmware
I-drive i11 Firmware
I-drive i12
Summary
  • (es) Se ha detectado una vulnerabilidad en i-Drive i11 e i12 hasta 20250227 y se ha clasificado como problemática. Este problema afecta a un procesamiento desconocido del componente APK. La manipulación conduce a credenciales codificadas de forma rígida. Es posible lanzar el ataque en el dispositivo físico. No ha sido posible identificar al responsable actual del mantenimiento del producto. Se debe suponer que el producto ha llegado al final de su vida útil.

03 Mar 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-03 20:15

Updated : 2025-03-05 14:52


NVD link : CVE-2025-1879

Mitre link : CVE-2025-1879

CVE.ORG link : CVE-2025-1879


JSON object : View

CWE
CWE-259

Use of Hard-coded Password

CWE-798

Use of Hard-coded Credentials