External risk intelligence

AmpedRF BT-AP 111 HTTP Admin Interface Authentication Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-9994

The vulnerability exists in an HTTP administration interface of an access point. Network appliances and their management interfaces are commonly deployed in configurations where they are reachable from the network, and lack of authentication on such an interface presents a significant exposure risk for devices intended for connectivity management.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in the Amp’ed RF BT-AP 111 Bluetooth access point, where its administrative interface lacks authentication. This means anyone on the network can access and potentially control the device, which could have significant implications for network security and data integrity.

  • Unauthenticated access to device management.
  • Critical flaw allows network control.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker on the network could directly access the Bluetooth access point's web administration page because it lacks any login security. This allows them to freely change settings, potentially disrupting or compromising the network services managed by the access point.

  • No authentication required to access.
  • HTTP admin interface is the trigger point.
  • Unauthorized access to network management.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could expose the Bluetooth access point's administrative interface to unauthorized network access. When this interface is reachable over a network, an attacker could potentially access and modify device configurations. There is no indication that Personally Identifiable Information (PII) or other sensitive data types are directly affected by this vulnerability.

  • Access point administrative settings at risk.
  • Unauthorized network access could occur.
  • Configuration changes may be possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given the nature of an unauthenticated HTTP administrative interface on a Bluetooth access point, ownership likely resides with the network or infrastructure team responsible for device management. The initial action should be to discover all instances of this access point, assess their network exposure, and confirm their business criticality to prioritize remediation efforts.

  • Network/Infrastructure team owns resolution.
  • Verify device exposure and criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Amp’ed RF BT-AP 111?

The Amp’ed RF BT-AP 111 is a specialized networking hardware device designed to bridge Bluetooth connectivity into a larger network infrastructure. It acts as a gateway, allowing administrators to manage Bluetooth communication and wireless traffic. Organizations typically deploy these units to extend connectivity for local wireless sensors or devices, relying on the built-in HTTP administration interface to configure operational settings, security parameters, and network routing.

What does CVE-2025-9994 mean for device security?

CVE-2025-9994 refers to a critical vulnerability involving missing authentication (CWE-306) and improper authentication (CWE-287). Essentially, the software governing the administration interface lacks any security gatekeeper. Because there is no requirement to provide credentials, the device treats every incoming web request as authorized, allowing any individual with network access to interact with sensitive administrative functions.

How does an attacker trigger this vulnerability?

The trigger path is straightforward: an attacker simply needs network connectivity that can reach the device's web-based administration page via HTTP. The vulnerability is triggered automatically upon accessing the interface URL. It is important to note that this is not triggered by physical interaction with the Bluetooth radio itself, but specifically by network-based communication directed at the administrative web service.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal labels this risk as 'Likely' because administrative interfaces for network appliances are often deployed in ways that are reachable across a local network. If your BT-AP 111 instance is accessible from your general network segment rather than an isolated, restricted management subnet, it faces a higher probability of unauthorized interaction by anyone on that network.

Do I need to update my Amp’ed RF BT-AP 111?

Your first step is to locate all deployed instances of this hardware to determine how widely they are distributed across your environment. Since the issue is a fundamental lack of authentication, verify whether these units are currently connected to broader network segments. Coordinate with your infrastructure team to assess if these devices can be moved to a private, non-routable management network to immediately reduce visibility while awaiting specific vendor guidance or firmware updates.

References