An issue was discovered in Dataphone A920 v2025.07.161103...
        
  Critical severity
        
          Unreviewed
      
        Published
          Oct 28, 2025 
          to the GitHub Advisory Database
          •
          Updated Oct 29, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Oct 28, 2025 
    
  
        Published to the GitHub Advisory Database
      Oct 28, 2025 
    
  
        Last updated
      Oct 29, 2025 
    
  
An issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public documentation can be crafted, where some fields can contain arbitrary or trivial data. Normally, such data should cause the device to reject the packet. However, due to a lack of validation, the device accepts it with no authetication and triggers the functionality instead.
References