VYPR
Medium severity6.8NVD Advisory· Published Jul 24, 2025· Updated Apr 15, 2026

CVE-2025-4395

CVE-2025-4395

Description

Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify system functionality.

This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.