CVE-2025-45583

Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the service using any combination of username and password.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:audi:universal_traffic_recorder_firmware:1.52:*:*:*:*:*:*:*
cpe:2.3:h:audi:universal_traffic_recorder:2.0:*:*:*:*:*:*:*

History

16 Oct 2025, 15:39

Type Values Removed Values Added
First Time Audi
Audi universal Traffic Recorder Firmware
Audi universal Traffic Recorder
CPE cpe:2.3:o:audi:universal_traffic_recorder_firmware:1.52:*:*:*:*:*:*:*
cpe:2.3:h:audi:universal_traffic_recorder:2.0:*:*:*:*:*:*:*
References () https://2barbie.notion.site/2024-Audi-UTR-2-0-Report-1bff0be688c680cb8795efe78732f8b9 - () https://2barbie.notion.site/2024-Audi-UTR-2-0-Report-1bff0be688c680cb8795efe78732f8b9 - Exploit, Third Party Advisory

15 Sep 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CWE CWE-287

12 Sep 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-12 21:15

Updated : 2025-10-16 15:39


NVD link : CVE-2025-45583

Mitre link : CVE-2025-45583

CVE.ORG link : CVE-2025-45583


JSON object : View

Products Affected

audi

  • universal_traffic_recorder
  • universal_traffic_recorder_firmware
CWE
CWE-287

Improper Authentication