CVE-2025-10285: Silabs.com Simplicity Studio v6

High severity, CVSS 7.4. EPSS: 0.2% chance of exploitation in the next 30 days.

The web interface of the Silicon Labs Simplicity Device Manager is exposed publicly and can be used to extract the NTLMv2 hash which an attacker could use to crack the user's domain password.

Affected products

  • Silabs.com Simplicity Studio v6: before 0.100.18 (fixed in 0.100.18)

Published 2025-12-04. Last modified 2026-06-17.