Junglewise Threat Intelligence

CVE-2025-61478: Vanderbilt Acre Security SPC5300.000 denial of service via spoofed SYN packets

CVE-2025-61478 · Severity: high · CVSS 7.5 · Published 2026-08-26

Executive brief

A network security appliance manufactured by Vanderbilt Industries is vulnerable to a denial of service attack when subjected to specially crafted spoofed network packets. An attacker with physical proximity to the device can send malicious packets that cause the appliance to become unresponsive, disrupting its ability to protect the network and potentially causing downtime.

Technical details

This vulnerability exists in the SPC5300.000 Main Board firmware version 3.14.1 and involves a denial of service condition triggered by spoofed TCP SYN packets. The attack requires physical proximity to the affected device or network segment. An attacker can craft malicious SYN packets that exhaust the device's resources or cause it to crash, preventing legitimate traffic from being processed. The vendor has assigned CVE-2025-61478 to track this issue; patch availability and affected version ranges should be confirmed with Vanderbilt Industries.

Affected products

  • Vanderbilt Industries Acre Security SPC5300.000 Main Board v.3.14.1

Timeline

  • 2026-08-26: disclosed

References

Related threats