CVE-2025-23405: Dario Health Dario Application Database And Internet-Based Server Infrastructure
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Unauthenticated log effects metrics gathering incident response efforts and potentially exposes risk of injection attacks (ex log injection).
Affected products
- Dario Health Dario Application Database And Internet-Based Server Infrastructure: any version
- Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Applications: before 5.8.7.0.36 (fixed in 5.8.7.0.36)
Published 2025-02-28. Last modified 2026-06-17.