# NVD CVE-2025-59404 - Bravo bootloader unlocked
> *Audited source extract. The dossier was used only as a lead; the underlying source was independently acquired and checked on 2026-07-20.*
## Source metadata
- **Publisher:** National Vulnerability Database / CVE Program
- **Original dossier URL:** https://nvd.nist.gov/vuln/detail/CVE-2025-59404
- **Resolved/canonical URL used:** https://nvd.nist.gov/vuln/detail/CVE-2025-59404
- **Publication date:** 2025-09-25
- **Underlying event or version:** Bravo build BRAVO_00.00_local_20241017
- **Archived:** 2026-07-20, from unauthenticated public access; no cookies, tokens, or login state retained
- **Wayback snapshot:** save failed on 2026-07-20 after the archive service returned HTTP 403; retry pending
## Verification verdict
**obsolete/version-specific** — CVE-2025-59404 supports the described unlocked bootloader for Bravo build BRAVO_00.00_local_20241017. The later CNA records often use n/a in the structured affected-product block, making the narrative build/app version the essential applicability limit. No independent current remediation attestation was located; the CVE was not in CISA KEV on July 20, 2026.
## Claim boundary
This source is authoritative only within the source class and limitations stated above.
## Extract
**CVE Program record:** CVE-2025-59404; state PUBLISHED; published 2025-09-25; last updated 2025-09-26.
**Structured affected block (`containers.cna.affected`):**
- n/a / n/a: status=affected; version=n/a
**Narrative applicability boundary used in this audit:** Bravo build BRAVO_00.00_local_20241017. When the structured affected block says `n/a`, the narrative build or application version is the controlling limit; it is not evidence about every deployed Flock device.
**Publication-safe verification summary:** CVE-2025-59404 supports the described unlocked bootloader for Bravo build BRAVO_00.00_local_20241017. The later CNA records often use n/a in the structured affected-product block, making the narrative build/app version the essential applicability limit. No independent current remediation attestation was located; the CVE was not in CISA KEV on July 20, 2026.
**Classification and severity:** CWE-1274 Improper Access Control for Volatile Memory Containing Boot Code; CVSS 7.5 HIGH.
The CNA JSON is preserved as a companion to the NVD HTML. Operational endpoints, credentials, access paths, and exploitation instructions are deliberately omitted from this extract.
**Wayback failure**: The bounded Save Page Now pass stopped after the archive service returned HTTP 403 on the first request. This source was not individually retried; retry pending.
## Notes
- Tier: 2 — Tier 2 primary public record.
- Operational exploitation steps, credentials, endpoints, and targeting details are omitted from this markdown extract; the public originals are retained for defensive verification.
- Cited by: see `citing_pages:` frontmatter; populated after wiki integration.