
Security advisory for CVE-2025-65855 - Multiple vulnerabilities in HelpFlash IoT OTA update mechanism
HelpFlash IoT OTA Update Multiple Vulnerabilities
Multiple vulnerabilities in the OTA firmware update mechanism of Netun Solutions HelpFlash IoT allow an attacker with brief physical access to execute arbitrary code.
CVE ID: CVE-2025-65855
Severity: HIGH
CVSS v3.1 Score: 7.6 (Researcher assessment - pending NVD analysis)
CVSS Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Official CVSS score will be published by NVD following their analysis.
Vendor: Netun Solutions S.L.
Product: HelpFlash IoT
Product Page: https://netun.com/en/products/help-flash-iot
Versions: v18_178_221102_ASCII_PRO_1R5_50 and prior
Component: OTA firmware update system (ESP-IDF v4.3.2)
Device Context:
HelpFlash IoT is a safety-critical emergency road signaling device mandated by Spanish traffic authority (DGT) as a replacement for traditional warning triangles in vehicles.
The device's OTA update mechanism contains multiple security issues:
Hard-coded WiFi Credentials (CWE-798)
HF-UpdateAP-5JvqFVHF-UpdateAP-5JvqFVUnauthenticated Update Server (CWE-494)
Cleartext Transmission (CWE-319)
No OTA Activation Authentication
An attacker with brief physical access can:
Attack Scalability: Identical credentials across all devices enable mass exploitation.
Complete proof of concept developed and validated on multiple devices. Attack successfully demonstrated:
PoC code available to vendor and security researchers under appropriate arrangements.
Vendor should implement:
Vendor was notified through INCIBE-CERT coordinated disclosure process. INCIBE-CERT confirmed no publication restrictions apply and authorized public disclosure.
Discovered by: Luis Miranda Acebedo
Contact: [email protected]