CVE-2025-59392: Elspec-Ltd g5dfr Firmware

Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.

On Elspec G5 devices through 1.2.2.19, a person with physical access to the device can reset the Admin password by inserting a USB drive (containing a publicly documented reset string) into a USB port.

Affected products

  • Elspec-Ltd g5dfr Firmware: before 1.2.3.13 (fixed in 1.2.3.13)

Published 2025-11-06. Last modified 2026-06-17.