Vulnerabilities (CVE)

Filtered by vendor Nerves-hub
Filtered by product Nerveshub
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-64097 1 Nerves-hub 1 Nerveshub 2026-02-17 N/A 9.8 CRITICAL
NervesHub is a web service that allows users to manage over-the-air (OTA) firmware updates of devices in the field. A vulnerability present starting in version 1.0.0 and prior to version 2.3.0 allowed attackers to brute-force user API tokens due to the predictable format of previously issued tokens. Tokens included user-identifiable components and were not cryptographically secure, making them susceptible to guessing or enumeration. The vulnerability could have allowed unauthorized access to use ...

Show More