CVE-2025-28232: Jmbroadcast JMB0150 Firmware

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without authentication.

Affected products

Published 2025-04-18. Last modified 2026-06-17.