{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.1",
    "cveMetadata": {
        "cveId": "CVE-2025-8762",
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "state": "PUBLISHED",
        "assignerShortName": "VulDB",
        "dateReserved": "2025-08-08T15:37:37.719Z",
        "datePublished": "2025-08-13T06:14:04.487Z",
        "dateUpdated": "2025-08-13T13:30:21.695Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
                "shortName": "VulDB",
                "dateUpdated": "2025-08-13T06:14:04.487Z"
            },
            "title": "INSTAR 2K+/4K UART improper physical access control",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "type": "CWE",
                            "cweId": "CWE-1263",
                            "lang": "en",
                            "description": "Improper Physical Access Control"
                        }
                    ]
                },
                {
                    "descriptions": [
                        {
                            "type": "CWE",
                            "cweId": "CWE-284",
                            "lang": "en",
                            "description": "Improper Access Controls"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "INSTAR",
                    "product": "2K+",
                    "versions": [
                        {
                            "version": "3.11.1 Build 1124",
                            "status": "affected"
                        }
                    ],
                    "modules": [
                        "UART Interface"
                    ]
                },
                {
                    "vendor": "INSTAR",
                    "product": "4K",
                    "versions": [
                        {
                            "version": "3.11.1 Build 1124",
                            "status": "affected"
                        }
                    ],
                    "modules": [
                        "UART Interface"
                    ]
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "A vulnerability was found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This issue affects some unknown processing of the component UART Interface. The manipulation leads to improper physical access control. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used."
                },
                {
                    "lang": "de",
                    "value": "Davon betroffen ist unbekannter Code der Komponente UART Interface. Durch das Manipulieren mit unbekannten Daten kann eine improper physical access control-Schwachstelle ausgenutzt werden. Ein Angriff setzt physischen Zugriff auf dem Zielobjekt voraus. Der Exploit steht zur öffentlichen Verfügung."
                }
            ],
            "metrics": [
                {
                    "cvssV4_0": {
                        "version": "4.0",
                        "baseScore": 7,
                        "vectorString": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P",
                        "baseSeverity": "HIGH"
                    }
                },
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "baseScore": 6.8,
                        "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R",
                        "baseSeverity": "MEDIUM"
                    }
                },
                {
                    "cvssV3_0": {
                        "version": "3.0",
                        "baseScore": 6.8,
                        "vectorString": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R",
                        "baseSeverity": "MEDIUM"
                    }
                },
                {
                    "cvssV2_0": {
                        "version": "2.0",
                        "baseScore": 7.2,
                        "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"
                    }
                }
            ],
            "timeline": [
                {
                    "time": "2025-08-13T00:00:00.000Z",
                    "lang": "en",
                    "value": "Advisory disclosed"
                },
                {
                    "time": "2025-08-13T02:00:00.000Z",
                    "lang": "en",
                    "value": "VulDB entry created"
                },
                {
                    "time": "2025-08-13T08:18:26.000Z",
                    "lang": "en",
                    "value": "VulDB entry last update"
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Michael Imfeld (modzero AG)",
                    "type": "finder"
                }
            ],
            "references": [
                {
                    "url": "https://vuldb.com/?id.319865",
                    "name": "VDB-319865 | INSTAR 2K+/4K UART improper physical access control",
                    "tags": [
                        "vdb-entry"
                    ]
                },
                {
                    "url": "https://vuldb.com/?ctiid.319865",
                    "name": "VDB-319865 | CTI Indicators (IOB, IOC)",
                    "tags": [
                        "signature",
                        "permissions-required"
                    ]
                },
                {
                    "url": "https://modzero.com/static/MZ-25-03_modzero_INSTAR.pdf",
                    "tags": [
                        "exploit"
                    ]
                }
            ]
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-08-13T13:30:16.418304Z",
                                "id": "CVE-2025-8762",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-08-13T13:30:21.695Z"
                }
            }
        ]
    }
}