# NVD CVE-2025-47823 - hardcoded system password in LPR firmware through 2.2
> *Audited source extract. The dossier was used only as a lead; the underlying source was independently acquired and checked on 2026-07-20.*
## Source metadata
- **Publisher:** National Vulnerability Database / CVE Program
- **Original dossier URL:** https://nvd.nist.gov/vuln/detail/CVE-2025-47823
- **Resolved/canonical URL used:** https://nvd.nist.gov/vuln/detail/CVE-2025-47823
- **Publication date:** 2025-06-27
- **Underlying event or version:** LPR firmware through 2.2
- **Archived:** 2026-07-20, from unauthenticated public access; no cookies, tokens, or login state retained
- **Wayback snapshot:** save failed on 2026-07-20 after the archive service returned HTTP 403; retry pending
## Verification verdict
**obsolete/version-specific** — CVE-2025-47823 supports the described LPR firmware through 2.2; hardcoded system password. The CNA description and NVD configuration range are not perfectly aligned for the gunshot-device boundary, so applicability must be confirmed against the exact model and firmware. No current fixed-version matrix was located, and absence from the CISA KEV catalog on July 20, 2026 does not mean unexploited.
## Claim boundary
The catalog product name 'LPR 2.2 Camera' is not established as the same identifier as firmware through 2.2.
## Extract
**CVE Program record:** CVE-2025-47823; state PUBLISHED; published 2025-06-27; last updated 2025-09-02.
**Structured affected block (`containers.cna.affected`):**
- Flock Safety / License Plate Reader: status=affected; version=0; lessThanOrEqual=2.2; versionType=custom
**Narrative applicability boundary used in this audit:** LPR firmware through 2.2. When the structured affected block says `n/a`, the narrative build or application version is the controlling limit; it is not evidence about every deployed Flock device.
**Publication-safe verification summary:** CVE-2025-47823 supports the described LPR firmware through 2.2; hardcoded system password. The CNA description and NVD configuration range are not perfectly aligned for the gunshot-device boundary, so applicability must be confirmed against the exact model and firmware. No current fixed-version matrix was located, and absence from the CISA KEV catalog on July 20, 2026 does not mean unexploited.
**Classification and severity:** CWE-259 Use of Hard-coded Password; CVSS 2.2 LOW.
The CNA JSON is preserved as a companion to the NVD HTML. Operational endpoints, credentials, access paths, and exploitation instructions are deliberately omitted from this extract.
**Additional identifier caveat:** The catalog product name 'LPR 2.2 Camera' is not established as the same identifier as firmware through 2.2.
**Wayback failure**: The bounded Save Page Now pass stopped after the archive service returned HTTP 403 on the first request. This source was not individually retried; retry pending.
## Notes
- Tier: 2 — Tier 2 primary public record.
- Operational exploitation steps, credentials, endpoints, and targeting details are omitted from this markdown extract; the public originals are retained for defensive verification.
- Cited by: see `citing_pages:` frontmatter; populated after wiki integration.