Mirion Medical picked up ICSMA-25-336-01 for its EC2 nuclear-medicine software, the NMIS and BioDose products, versions before 23.0. Five high-severity CVEs. Hard-coded credentials, CVE-2025-64778. Client-side authentication, CVE-2025-61940 at 8.3, meaning the app trusts the browser to decide who is allowed in. Plus incorrect permission assignments up to 8.4.

Hard-coded credentials enter a codebase for ordinary reasons. A build needs a service account, an installer needs to reach a database, two components need to trust each other, and a fixed secret written into the software is the fastest way to make that work on the bench. The secret then ships to every customer identically, which turns a development convenience into a master key that anyone who reads the binary can copy.

Chained, they let an attacker modify executables, read sensitive data, gain unauthorized access and run arbitrary code. Joe Dillon reported it.

The setting sharpens the stakes. The software runs inside nuclear-medicine, a field where it supports the handling of radioactive material and the clinical work built around it. An attacker able to read sensitive data or run code on it sits against records clinicians rely on to be exactly what the instruments produced, and the integrity of those records is not a paperwork matter in that kind of department.

Client-side authentication is a product built as if the network were friendly. It never is. Auth decisions belong on the server, every time.

The fixed secret and the browser-side check describe the same underlying belief, that the software would only ever run on a trusted and quiet network. That belief is a legacy of an era when clinical instruments were islands. The advisory path, a coordinated identifier and a fixed release, is now the mechanism by which such an assumption gets corrected in public, product by product.