CVE-2025-66237: Sunbird Dcim Dctrack

Medium severity, CVSS 6.7. EPSS: 0.1% chance of exploitation in the next 30 days.

DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to administer the database, escalate privileges on the platform or execute system commands on the host.

Affected products

  • Sunbird Dcim Dctrack: up to and including v9.2.0
  • Sunbird Power Iq: up to and including v9.2.0

Published 2025-12-04. Last modified 2026-09-25.