Radiometrics Vizair vulnerabilities
3 known vulnerabilities affecting radiometrics/vizair.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3
Vulnerabilities
Page 1 of 1
CVE-2025-61945P2CRITICALCVSS 9.8fixed in 2025-08fixed in 08/20252025-11-04
CVE-2025-61945 [CRITICAL] CWE-306 CVE-2025-61945: Radiometrics VizAir is vulnerable to any remote attacker via access to the admin panel of the VizAir
Radiometrics VizAir is vulnerable to any remote attacker via access to the admin panel of the VizAir system without authentication. Once inside, the attacker can modify critical weather parameters such as wind shear alerts, inversion depth, and CAPE values, which are essential for accurate weather forecasting and flight safety. This unauthorized a
nvd
CVE-2025-61956P2CRITICALCVSS 9.8fixed in 2025-08fixed in 08/20252025-11-04
CVE-2025-61956 [CRITICAL] CWE-306 CVE-2025-61956: Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, suc
Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access and API requests. Attackers can modify configurations without authentication, potentially manipulating active runway settings and misleading air traffic control (ATC) and pilots. Additionally, manipulated meteorological data could
nvd
CVE-2025-54863P3CRITICALCVSS 9.8fixed in 2025-08fixed in 08/20252025-11-04
CVE-2025-54863 [CRITICAL] CWE-522 CVE-2025-54863: Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly access
Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly accessible configuration file. This allows attackers to remotely alter weather data and configurations, automate attacks against multiple instances, and extract sensitive meteorological data, which could potentially compromise airport operations. Addition
nvd