CVE-2025-27579: Bitaxe Esp-Miner

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

In Bitaxe ESP-Miner before 2.5.0 with AxeOS, one can use an /api/system CSRF attack to update the payout address (aka stratumUser) for a Bitaxe Bitcoin miner, or change the frequency and voltage settings.

Affected products

  • Bitaxe Esp-Miner: before 2.5.0 (fixed in 2.5.0)

Published 2025-03-03. Last modified 2026-06-17.