External risk intelligence

Novakon P Series Buffer Overflow Allows Root Access Without Authentication.

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2025-9962

The affected product is a Human Machine Interface (HMI) series, which are commonly deployed as network-accessible industrial gateway or monitoring devices. HMIs are frequently reachable over internal or external networks for remote management and process control, placing them in a position where they are often exposed to network-connected environments.

Buffer Overflow

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Novakon's P series Human Machine Interface (HMI) devices, allowing unauthenticated attackers to gain full system control. This issue affects specific versions of the P series, potentially exposing critical industrial control systems to unauthorized access and manipulation.

  • Unauthenticated attackers can take full control.
  • HMIs are often network-connected industrial systems.
  • Confirm relevance and exposure of P series devices.

Attack Path

How an attacker could exploit the issue

An attacker could reach the vulnerable component by exploiting the network accessibility of the Novakon P series Human Machine Interface (HMI). Once network access is established, the attacker can interact with the device and trigger a buffer overflow, potentially leading to the highest level of system control.

  • Network exposure is required.
  • Triggered by a buffer overflow.
  • Risk is root permission acquisition.

Live Threat

Current exploitation, exposure, and threat context

A buffer overflow in Novakon P series devices could allow an unauthenticated attacker to gain root privileges. This could affect the device's operational integrity and any data it processes or controls when accessible over a network.

  • Device operating system and control functions.
  • Unauthenticated network access to the device.
  • Complete system compromise and unauthorized control.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Novakon P series HMIs likely requires action from both the infrastructure or platform team managing the devices and the specific application owners who rely on them for operational control. The immediate first step is to inventory all deployed Novakon P series devices, confirm their network accessibility and criticality to business operations, and identify the accountable system owner for each instance. A targeted remediation plan can then be developed based on the assessed risk.

  • Identify Novakon P series device owners.
  • Verify network reachability and criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Novakon P series?

The Novakon P series is a line of Human Machine Interface (HMI) devices. These industrial terminals act as gateways or control panels that allow operators to monitor and interact with automated machinery and industrial processes in manufacturing or infrastructure environments.

What does the CWE-120 classification mean for CVE-2025-9962?

CWE-120 refers to a buffer overflow, a memory safety issue where a program writes more data to a memory buffer than it can hold. In this CVE, the flaw allows unauthorized data to overwrite adjacent memory, which an attacker can leverage to execute arbitrary commands and gain root-level privileges.

How is this vulnerability triggered?

The vulnerability is triggered by sending specifically crafted network traffic to the affected HMI. It requires network connectivity to the device. Notably, the flaw does not require the attacker to provide credentials or undergo any authentication process to successfully trigger the overflow.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal identifies that because these HMI devices often serve as network-accessible gateways, they are frequently reachable via internal or external networks. If your Novakon P series unit is connected to a network, its accessibility significantly increases the potential for unauthorized interaction.

What should I do if I use Novakon P series HMIs?

Start by inventorying your environment to locate all deployed P series units. Once identified, verify their network reachability and determine their role in your operations. Consult the manufacturer's official security guidance to identify the necessary firmware update to address this vulnerability.

References