Empty Password in Configuration File in MyCareLink Patient Monitor model 24950 and MyCareLink Patient Monitor model 24952 - CVE-2025-4395
Published: July 25, 2025
Vulnerability identifier: #VU113208
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-4395
CWE-ID: CWE-258
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to the affected product has a built-in user account with an empty password. An attacker with physical access can log in with no password and access or modify system functionality.
Affected software
MyCareLink Patient Monitor model 24950
MyCareLink Patient Monitor model 24952
MyCareLink Patient Monitor model 24952
How to mitigate CVE-2025-4395
Install updates from vendor's website.