# NVD CVE-2025-59405 - monitoring credential embedded in peripheral app > *Audited source extract. The dossier was used only as a lead; the underlying source was independently acquired and checked on 2026-07-20.* ## Source metadata - **Publisher:** National Vulnerability Database / CVE Program - **Original dossier URL:** https://nvd.nist.gov/vuln/detail/CVE-2025-59405 - **Resolved/canonical URL used:** https://nvd.nist.gov/vuln/detail/CVE-2025-59405 - **Publication date:** 2025-10-02 - **Underlying event or version:** peripheral app 7.38.3 - **Archived:** 2026-07-20, from unauthenticated public access; no cookies, tokens, or login state retained - **Wayback snapshot:** save failed on 2026-07-20 after the archive service returned HTTP 403; retry pending ## Verification verdict **obsolete/version-specific** — CVE-2025-59405 supports the described embedded monitoring credential for peripheral app 7.38.3. The later CNA records often use n/a in the structured affected-product block, making the narrative build/app version the essential applicability limit. No independent current remediation attestation was located; the CVE was not in CISA KEV on July 20, 2026. ## Claim boundary This source is authoritative only within the source class and limitations stated above. ## Extract **CVE Program record:** CVE-2025-59405; state PUBLISHED; published 2025-10-02; last updated 2025-11-24. **Structured affected block (`containers.cna.affected`):** - n/a / n/a: status=affected; version=n/a **Narrative applicability boundary used in this audit:** peripheral app 7.38.3. When the structured affected block says `n/a`, the narrative build or application version is the controlling limit; it is not evidence about every deployed Flock device. **Publication-safe verification summary:** CVE-2025-59405 supports the described embedded monitoring credential for peripheral app 7.38.3. The later CNA records often use n/a in the structured affected-product block, making the narrative build/app version the essential applicability limit. No independent current remediation attestation was located; the CVE was not in CISA KEV on July 20, 2026. **Classification and severity:** CWE-200 Exposure of Sensitive Information to an Unauthorized Actor; CVSS 7.5 HIGH. The CNA JSON is preserved as a companion to the NVD HTML. Operational endpoints, credentials, access paths, and exploitation instructions are deliberately omitted from this extract. **Wayback failure**: The bounded Save Page Now pass stopped after the archive service returned HTTP 403 on the first request. This source was not individually retried; retry pending. ## Notes - Tier: 2 — Tier 2 primary public record. - Operational exploitation steps, credentials, endpoints, and targeting details are omitted from this markdown extract; the public originals are retained for defensive verification. - Cited by: see `citing_pages:` frontmatter; populated after wiki integration.