Empty Password in Configuration File in MyCareLink Patient Monitor model 24950 and MyCareLink Patient Monitor model 24952 - CVE-2025-4395

 

Empty Password in Configuration File in MyCareLink Patient Monitor model 24950 and MyCareLink Patient Monitor model 24952 - CVE-2025-4395

Published: July 25, 2025


Vulnerability identifier: #VU113208
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-4395
CWE-ID: CWE-258
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to compromise the target system.

The vulnerability exists due to the affected product has a built-in user account with an empty password. An attacker with physical access can log in with no password and access or modify system functionality.


Affected software

MyCareLink Patient Monitor model 24950
MyCareLink Patient Monitor model 24952

How to mitigate CVE-2025-4395

Install updates from vendor's website.


External References

Related Security Bulletins