Radiometrics VizAir is vulnerable to a lack of...
Critical severity
Unreviewed
Published
Nov 4, 2025
to the GitHub Advisory Database
•
Updated Nov 4, 2025
Description
Published by the National Vulnerability Database
Nov 4, 2025
Published to the GitHub Advisory Database
Nov 4, 2025
Last updated
Nov 4, 2025
Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access and API requests. Attackers can modify configurations without authentication, potentially manipulating active runway settings and misleading air traffic control (ATC) and pilots. Additionally, manipulated meteorological data could mislead forecasters and ATC, causing inaccurate flight planning.
References