This security advisory addresses one vulnerability identified in serial device servers.
CVE-2026-10825
Improper JSON Input Validation in WebSocket API Leads to Denial of Service
A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests. A low-privileged authenticated attacker can send a specially crafted request that causes service disruption and may result in an unexpected device reboot.
Given the high severity of these issues, users should apply the solutions immediately to reduce security risks.
The Identified Vulnerability Type and Potential Impact
| CVE ID |
Vulnerability Type |
Impact |
| CVE-2026-10825 |
CWE-1287: Improper Validation of Specified Type of Input
|
CAPEC-28: Fuzzing |
Vulnerability Scoring Details
|
CVE ID
|
Base Score
|
Vector
|
Severity |
Unauthenticated
Remote Exploits
|
| CVE-2026-10825 |
CVSS 4.0: 7.1
|
AV:N/AC:L/AT:N/PR:L/UI:N/
VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
|
High |
No |