CVE-2025-3705
A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of special elements used in an OS Command (‘OS Command Injection’) when loading a config file from a USB drive.
More information : https://certvde.com/en/advisories/VDE-2025-030
