CVEPublished 2026-06-22Modified 2026-07-070 articles on news5 live referencesNVD data

CVE-2025-4994

Vulnerability data via NVD (ingested)

CVSS v3.1
EPSS percentile
10
Exploit Prediction Scoring System · top 90% of all CVEs
Description

The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows attackers to bypass authentication requirements and access the device's configuration service via the Bluetooth Low Energy (BLE) interface. Consequently, an attacker within wireless range can gain unauthorized administrative access to the device configuration.

Timeline
Published 2026-06-22
Modified 2026-07-07

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub (3)

We haven't classified any articles referencing CVE-2025-4994 yet. The external references above still apply.