CVE-2025-29270

Critical severity, CVSS 10.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the admin panel and complete control of the device.

Published 2025-10-31. Last modified 2026-06-17.