Insecure Storage of Sensitive Information in iND products - CVE-2025-53507
Published: September 15, 2025
Vulnerability identifier: #VU115205
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-53507
CWE-ID: CWE-922
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insecure storage of sensitive information. A remote attacker can gain access to sensitive information on the system.
Affected software
HL330-DLS (for module MC7700)
HL330-DLS (for module MC7330)
F2L Assist-SS-E
LM-100
F2L Assist-SS-A
LM-200 (for module AMP570)
L2X Assist-RS-E
LM-200 (for module EC25-J)
L2X Assist-RS-A
L2X Assist
HL330-DLS (for module MC7330)
F2L Assist-SS-E
LM-100
F2L Assist-SS-A
LM-200 (for module AMP570)
L2X Assist-RS-E
LM-200 (for module EC25-J)
L2X Assist-RS-A
L2X Assist
How to mitigate CVE-2025-53507
Install updates from vendor's website.
F2L Assist-SS-E - update to 1.02
LM-100 - update to 1.03
F2L Assist-SS-A - update to 1.04
LM-200 (for module AMP570) - update to 1.03
L2X Assist-RS-E - update to 1.13
LM-200 (for module EC25-J) - update to 1.06e
L2X Assist-RS-A - update to 1.12
L2X Assist - update to 2.02
LM-100 - update to 1.03
F2L Assist-SS-A - update to 1.04
LM-200 (for module AMP570) - update to 1.03
L2X Assist-RS-E - update to 1.13
LM-200 (for module EC25-J) - update to 1.06e
L2X Assist-RS-A - update to 1.12
L2X Assist - update to 2.02