← back
CVE-2025-3927

CVE-2025-3927

CVSS 9.8 CRITICALEPSS 0.5%
Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with the target IP address to connect and compromise the device, potentially pivoting to connected network or hardware devices.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Digigram · PYKO-OUT

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →