CVE-2025-61480CWE-294CWE-354CWE-362CWE-400denial-of-service

CVE-2025-61480

High · published August 27, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
2.6
In the wild
Unconfirmed
What it is

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00126 · 2.6th percentile
Weaknesses
CWE-294 · Authentication Bypass by Capture-replay; CWE-354 · Improper Validation of Integrity Check Value; CWE-362 · Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'); CWE-400 · Uncontrolled Resource Consumption
Published
2026-08-27T01:16Z
References (1)
EPSS history
Timeline
  • 28 AUG 06:23Z
    EPSS moved — → 0%
    epss
  • 26 AUG 00:00Z
    An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via…
    cvelistv5