Description

The Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which accepts unauthenticated plaintext commands for controlling streaming, recording, formatting storage devices, and system reboot. This interface, referred to as the "ATEM Ethernet Protocol 1.0", provides complete device control without requiring credentials or encryption. An attacker on the same network (or with remote access to the exposed port) can exploit this interface to execute arbitrary streaming commands, erase disks, or shut down the device - effectively gaining full remote control.

INFO

Published Date :

2025-09-22T00:00:00.000Z

Last Modified :

2025-10-28T20:09:54.728Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-57440 vulnerability.

Vendors Products
Blackmagic
  • Atem Mini Pro
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-57440.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact