Critical Information on Vulnerability from Screenshot CVE ID: CVE-2025-63221 Product: Axel Technology puma Affected Versions: Firmware versions 0.8.5 to 1.0.3 Vendor: Axel Technology Vendor Homepage: https://www.axeltechnology.com/ Description Axel Technology puma devices are vulnerable to Broken Access Control due to missing authentication on the endpoint. Unauthenticated remote attackers can list user accounts, create new administrative users, delete users, and modify system settings, leading to full compromise of the device. Vulnerable Endpoints Severity Severity Level: High Recommendations Implement mandatory authentication for all sensitive endpoints. Enforce role-based access control (RBAC). Restrict administrative endpoints to trusted IP addresses. Ensure secure session handling. Validate POST parameters. Affected Components Access Control: Direct access to sensitive administrative endpoints without authentication. User Management: Ability to add, modify, and delete user accounts without authentication. Privilege Escalation: Attackers can gain administrative control over the system. Attack Vectors