CVE-2025-13510 PUBLISHED

Iskra iHUB and iHUB Lite has a Missing Authentication for Critical Function vulnerabilitiy

Assigner: icscert
Reserved: 21.11.2025 Published: 02.12.2025 Updated: 02.12.2025

The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authentication, allowing unauthenticated users to access and modify critical device settings.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Iskra
Product iHUB and iHUB Lite
Versions Default: unaffected
  • Version All versions is affected

Credits

  • Souvik Kandar finder

References

Problem Types

  • CWE-306 Missing Authentication for Critical Function CWE