You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2025-10127
About this tag
CVE-2025-10127 is a critical pre-authentication password reset vulnerability affecting Daikin Security Gateway appliances. The flaw allows an unauthenticated attacker to reset device credentials to factory defaults, potentially gaining full control of the gateway and any connected systems. The issue was discovered by researcher Gjoko Krstic and has a high severity rating, with public proof-of-concept exploit code available. Discussions on WindowsForum cover the technical details, impact, and mitigation steps for this vulnerability, which is relevant for administrators managing Daikin devices in enterprise or industrial environments.
Daikin’s Security Gateway is affected by a critical pre‑authentication password‑reset flaw that lets an unauthenticated attacker reset device credentials to the factory default and take control of the appliance and any connected systems — the issue is tracked as CVE‑2025‑10127 and rated highly...