#VU112065 Use of a broken or risky cryptographic algorithm in Sight Bulb Pro Firmware ZJ_CG32-2201 - CVE-2025-6521
Published: July 1, 2025
Vulnerability identifier: #VU112065
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-6521
CWE-ID: CWE-327
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerable software:
Sight Bulb Pro Firmware ZJ_CG32-2201
Sight Bulb Pro Firmware ZJ_CG32-2201
Software vendor:
Trend Makers
Trend Makers
Description
The vulnerability allows a remote user to compromise the target system.
The vulnerability exists due to use of a broken or risky cryptographic algorithm. A remote administrator on the local network can decrypt communications and gain access to sensitive information on the system.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.