The SentinelOne Annual Threat Report - A Defenders Guide from the FrontlinesThe SentinelOne Annual Threat ReportGet the Report
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2025-25211

CVE-2025-25211: CHOCO TEI Auth Bypass Vulnerability

CVE-2025-25211 is an authentication bypass flaw in CHOCO TEI WATCHER mini (IB-MCT001) caused by weak password requirements, enabling brute-force attacks. This article covers technical details, affected versions, and mitigation.

Updated: May 15, 2026

CVE-2025-25211 Overview

CVE-2025-25211 is a weak password requirements vulnerability [CWE-521] affecting all versions of the CHOCO TEI WATCHER mini (IB-MCT001), a production-line monitoring camera manufactured by Inaba Denki Sangyo. The device enforces insufficient password complexity rules, allowing attackers to conduct brute-force attacks against the authentication interface. Successful exploitation grants unauthorized access to the device's management functions, which include live video feeds and recording controls used on factory floors.

Critical Impact

A remote, unauthenticated attacker can brute-force account credentials over the network and gain full access to the camera, exposing production-line surveillance footage and enabling tampering with recording functions.

Affected Products

  • CHOCO TEI WATCHER mini (IB-MCT001) — all versions
  • Inaba Denki Sangyo production-line monitoring cameras
  • Industrial control system (ICS) deployments using IB-MCT001 for stoppage recording

Discovery Timeline

  • 2025-03-31 - CVE-2025-25211 published to the National Vulnerability Database (NVD)
  • 2026-04-15 - Last updated in NVD database

Technical Details for CVE-2025-25211

Vulnerability Analysis

The IB-MCT001 device implements authentication without enforcing password complexity, length, or lockout controls sufficient to resist automated guessing. An attacker reaching the device over the network can iterate through credential candidates until valid authentication succeeds. Because the camera is typically deployed on operational technology (OT) segments to record production-line stoppages, compromise has direct operational consequences.

The issue is classified under [CWE-521: Weak Password Requirements]. Once authenticated, the attacker inherits administrative control over the device, with no secondary authorization layer to limit lateral activity within the device's web interface.

Root Cause

The firmware does not require users to set passwords meeting modern complexity standards and lacks compensating controls such as rate limiting, account lockout, or multi-factor authentication. This design choice leaves the authentication surface trivially attackable by credential-guessing tools.

Attack Vector

The attack is network-based and requires no prior privileges or user interaction. An attacker with reachability to the device's management interface, typically on TCP port 80/443 or the device's proprietary protocol, can submit automated authentication requests. Devices exposed to the internet or reachable from compromised IT segments are at highest risk. Refer to the CISA ICS Advisory ICSA-25-084-04 and JVN Vulnerability Report for vendor-confirmed attack surface details.

No verified public proof-of-concept code is available. The exploitation pattern follows standard credential brute-force methodology against the device's HTTP authentication endpoint, as described in the Nozomi Networks research.

Detection Methods for CVE-2025-25211

Indicators of Compromise

  • Repeated failed HTTP authentication attempts to IB-MCT001 management interfaces from a single source within a short time window
  • Successful logins from external or unexpected internal IP addresses to production-line camera endpoints
  • Unscheduled configuration changes, firmware modifications, or new user accounts on the device
  • Anomalous outbound traffic from the camera segment, indicating live video streaming to attacker-controlled hosts

Detection Strategies

  • Deploy network intrusion detection signatures that flag high-frequency authentication failures against IB-MCT001 HTTP endpoints
  • Correlate authentication logs against IT/OT boundary firewall flow records to identify unauthorized cross-zone access
  • Baseline normal access patterns to the camera management interface and alert on deviations such as off-hours logins

Monitoring Recommendations

  • Forward device and switch logs from the OT segment to a centralized SIEM for retention and correlation
  • Monitor for new TCP sessions to IB-MCT001 from sources outside an explicit allowlist
  • Track firmware version and configuration hashes to detect unauthorized modification post-compromise

How to Mitigate CVE-2025-25211

Immediate Actions Required

  • Remove IB-MCT001 devices from direct internet exposure and place them behind a firewall on an isolated OT VLAN
  • Change all default and weak passwords to long, unique values using the maximum complexity the device permits
  • Restrict management interface access to a small set of administrative jump hosts using strict ACLs
  • Review device logs for prior authentication anomalies that may indicate existing compromise

Patch Information

Refer to the vendor advisory Inaba ChocoMini Vulnerability PDF and CISA ICS Advisory ICSA-25-084-04 for the latest remediation guidance. At the time of advisory publication, the vulnerability affected all versions of IB-MCT001, and operators were directed to apply network-level mitigations pending vendor fixes.

Workarounds

  • Segment production-line cameras onto a dedicated VLAN with no route to the internet or general corporate network
  • Place a reverse proxy or VPN concentrator in front of the device to enforce strong authentication and rate limiting upstream
  • Apply firewall rules permitting management traffic only from explicitly authorized engineering workstations
  • Disable any unused network services and protocols on the device to reduce attack surface
bash
# Configuration example: restrict access to IB-MCT001 management via iptables
# Allow management only from a dedicated jump host (192.0.2.10)
iptables -A FORWARD -s 192.0.2.10 -d 10.20.30.40 -p tcp --dport 80 -j ACCEPT
iptables -A FORWARD -s 192.0.2.10 -d 10.20.30.40 -p tcp --dport 443 -j ACCEPT
iptables -A FORWARD -d 10.20.30.40 -p tcp --dport 80 -j DROP
iptables -A FORWARD -d 10.20.30.40 -p tcp --dport 443 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechChoco Tei Watcher

  • SeverityCRITICAL

  • CVSS Score9.8

  • EPSS Probability0.46%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-521
  • Technical References
  • JVN Vulnerability Report

  • CISA ICS Advisory ICSA-25-084-04

  • Inaba ChocoMini Vulnerability PDF

  • Nozomi Networks Blog on Camera Vulnerabilities
  • Related CVEs
  • CVE-2025-24517: CHOCO TEI WATCHER Auth Bypass Flaw

  • CVE-2025-26689: CHOCO TEI WATCHER mini Auth Bypass Flaw
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English