CVE-2025-36755CWE-1191CWE-1244

CleverDisplay BlueOne unauthorized BIOS access through physical USB keyboard

Low · published December 12, 2025

CVSS v4.0
2.4
EPSS
0%
Percentile
5.9
In the wild
Unconfirmed
What it is

The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under normal operating conditions. Researchers demonstrated that, after cicumventing the device’s protective enclosure, it was possible to connect a USB keyboard and press ESC during boot to access the BIOS setup interface. BIOS settings could be viewed but not modified. This behavior slightly increases the attack surface by exposing internal system information (CWE-1244) once the enclosure is removed, but does not allow integrity or availability compromise under standard or tested configurations.

The record
Technical detail
CVSS v4.0
2.4 · LOW
Vector
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/S:N/AU:N/V:D/RE:L/U:Green
EPSS
0.00164 · 5.9th percentile
Weaknesses
CWE-1191 · On-Chip Debug and Test Interface With Improper Access Control; CWE-1244 · Internal Asset Exposed to Unsafe Debug Access Level or State
Published
2025-12-12T14:58Z
EPSS history
Timeline
  • 12 DEC 14:58Z
    CleverDisplay BlueOne unauthorized BIOS access through physical USB keyboard
    cvelistv5