CVE-2025-23405: Dario Health Dario Application Database And Internet-Based Server Infrastructure

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Unauthenticated log effects metrics gathering incident response efforts and potentially exposes risk of injection attacks (ex log injection).

Affected products

  • Dario Health Dario Application Database And Internet-Based Server Infrastructure: any version
  • Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Applications: before 5.8.7.0.36 (fixed in 5.8.7.0.36)

Published 2025-02-28. Last modified 2026-06-17.