Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the service using any combination of username and password.
References
Link | Resource |
---|---|
https://2barbie.notion.site/2024-Audi-UTR-2-0-Report-1bff0be688c680cb8795efe78732f8b9 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
16 Oct 2025, 15:39
Type | Values Removed | Values Added |
---|---|---|
First Time |
Audi
Audi universal Traffic Recorder Firmware Audi universal Traffic Recorder |
|
CPE | cpe:2.3:o:audi:universal_traffic_recorder_firmware:1.52:*:*:*:*:*:*:* cpe:2.3:h:audi:universal_traffic_recorder:2.0:*:*:*:*:*:*:* |
|
References | () https://2barbie.notion.site/2024-Audi-UTR-2-0-Report-1bff0be688c680cb8795efe78732f8b9 - Exploit, Third Party Advisory |
15 Sep 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
CWE | CWE-287 |
12 Sep 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-12 21:15
Updated : 2025-10-16 15:39
NVD link : CVE-2025-45583
Mitre link : CVE-2025-45583
CVE.ORG link : CVE-2025-45583
JSON object : View
Products Affected
audi
- universal_traffic_recorder
- universal_traffic_recorder_firmware
CWE
CWE-287
Improper Authentication