PatchSiren cyber security CVE debrief
CVE-2025-26689 Inaba Denki Sangyo Co., Ltd. CVE debrief
CVE-2025-26689 is a critical vulnerability affecting Inaba Denki Sangyo CHOCO TEI WATCHER mini (IB-MCT001). According to the CISA CSAF advisory, a remote attacker can send a specially crafted HTTP request and may be able to obtain or delete product data and/or alter product settings. The advisory maps to a CVSS 3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, which is consistent with the published 9.8 critical severity. The vendor-provided mitigations focus on reducing exposure: keep the product on a LAN, block untrusted network access, use a firewall or VPN if Internet access is required, and restrict operation to authorized users.
- Vendor
- Inaba Denki Sangyo Co., Ltd.
- Product
- CHOCO TEI WATCHER mini (IB-MCT001)
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-03-25
- Original CVE updated
- 2025-03-25
- Advisory published
- 2025-03-25
- Advisory updated
- 2025-03-25
Who should care
Organizations that operate or administer CHOCO TEI WATCHER mini (IB-MCT001), especially industrial, facility, or OT environments where the device is reachable over a network. Security teams should pay attention if the product is exposed beyond a trusted LAN, if remote access is enabled, or if operational data and settings are sensitive.
Technical summary
The advisory states that a remote attacker can exploit a specially crafted HTTP request against the product. The stated impact includes unauthorized data access, data deletion, and settings modification. The affected product scope in the CSAF is listed as vers:all/* for CHOCO TEI WATCHER mini (IB-MCT001), and the issue is presented as network-reachable with no user interaction required in the supplied CVSS vector. No fixed version is included in the supplied corpus; the published guidance emphasizes network isolation and access control as immediate mitigations.
Defensive priority
Highest priority for any environment where the device is reachable from untrusted networks or where its data and configuration are business-critical. Because the vulnerability is network-based, unauthenticated, and rated critical, exposure reduction and access restriction should be addressed immediately.
Recommended defensive actions
- Place the product only on a trusted LAN and block access from untrusted networks and hosts with firewalls.
- If Internet access is required, place the device behind a firewall or VPN and restrict exposure to the minimum necessary.
- Restrict product operation, including microSD card handling, to authorized users only.
- Review the associated vendor advisory and JVNVU#91154745 for any additional vendor guidance.
- Verify whether the device is reachable from any routed, remote, or third-party network segment and close unnecessary paths.
- Apply standard industrial control system defensive practices referenced by CISA for segmentation, access control, and monitoring.
Evidence notes
The CISA CSAF advisory for ICSA-25-084-04 states: "If a remote attacker sends a specially crafted HTTP request to the product, the product's data may be obtained or deleted, and/or the product's settings may be altered." The product tree identifies "Inaba Denki Sangyo Co., Ltd. CHOCO TEI WATCHER mini (IB-MCT001): vers:all/*" as affected. The remediations section recommends LAN-only use, blocking untrusted access, using a firewall or VPN when Internet access is required, and restricting operation to authorized users. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, matching the critical severity provided in the record.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-26689 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-26689
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-26689 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-26689
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-084-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-084-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.