GPU VulnDB

Database/Firmware, BMC & network fabric

ATEN eco DC (DCIM/environmental management platform): The web interface doesn't check a user's assigned role

CVE-2025-6685Firmware, BMC & network fabricZDI-25-650curated

Impact

The web interface doesn't check a user's assigned role before acting on their requests, so an authenticated low-privileged user can escalate to actions normally reserved for administrators on the datacenter-infrastructure-management platform — which typically has visibility and control hooks into PDUs and environmental sensors across the facility.

Who can reach it

Requires a valid but low-privileged account on ATEN eco DC; the attacker sends requests for admin-level functions that the server fails to gate on role.

What to do

Software upgrade to the patched eco DC release per ATEN's advisory. This is a server-side application (not per-rack firmware), so it's a single upgrade rather than a fleet-wide rollout, but audit who has any account on it since the bug turns any low-privileged login into an admin one.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.