CVE-2025-44003: Gallagher T-Series Readers

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Missing Release of Resource after Effective Lifetime (CWE-772) in the Gallagher T-Series Reader allows an attacker with physical access to the reader to perform a limited denial of service when 125 kHz Card Technology is enabled. This issue affects T-Series Readers: 9.20 prior to vCR9.20.250213a (distributed in 9.20.1827 (MR2)), 9.10 prior to vCR9.10.250213a (distributed in 9.10.2692(MR5)), 9.00 prior to vCR9.00.250619a (distributed in  vEL9.00.3371 (MR7)),  all versions of 8.90 and prior.

Affected products

  • Gallagher T-Series Readers: up to and including 8.90

Published 2025-07-10. Last modified 2026-06-17.