The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under normal operating conditions. Researchers demonstrated that, after cicumventing the device’s protective enclosure, it was possible to connect a USB keyboard and press ESC during boot to access the BIOS setup interface. BIOS settings could be viewed but not modified. This behavior slightly increases the attack surface by exposing internal system information (CWE-1244) once the enclosure is removed, but does not allow integrity or availability compromise under standard or tested configurations.
History

Fri, 12 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Description The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under normal operating conditions. Researchers demonstrated that, after cicumventing the device’s protective enclosure, it was possible to connect a USB keyboard and press ESC during boot to access the BIOS setup interface. BIOS settings could be viewed but not modified. This behavior slightly increases the attack surface by exposing internal system information (CWE-1244) once the enclosure is removed, but does not allow integrity or availability compromise under standard or tested configurations.
Title CleverDisplay BlueOne unauthorized BIOS access through physical USB keyboard
Weaknesses CWE-1191
CWE-1244
References
Metrics cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/S:N/AU:N/V:D/RE:L/U:Green'}


cve-icon MITRE

Status: PUBLISHED

Assigner: DIVD

Published: 2025-12-12T14:58:22.970Z

Updated: 2025-12-13T08:16:14.495Z

Reserved: 2025-04-15T21:54:36.815Z

Link: CVE-2025-36755

cve-icon Vulnrichment

Updated: 2025-12-12T18:50:12.194Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-12T15:15:53.433

Modified: 2025-12-12T15:17:31.973

Link: CVE-2025-36755

cve-icon Redhat

No data.