Vulnerability of missing authentication in media player
CVE Identifier: CVE-2025-12049
Description
The following Media Player has missing authentication vulnerability (CVE-2025-12049) that allow an attacker to:
- Execute arbitrary commands or programs.
- Deliver arbitrary content from the authoring software.
Models
MP-01
Workaround
Apply following workaround to avoid the effects of this vulnerability.
- Use the product only in a safe intranet protected by a firewall and do not connect the product to the Internet.
The above workaround prevents illegal access to the product.
Reference
Acknowledgements
Thanks to Mr. Souvik Kandar of MicroSec (microsec.io) for reporting this vulnerability.