The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials.
Fixes

Solution

It is recommended to update the device to versionĀ  61.00.01.03


Workaround

No workaround given by the vendor.

References
History

Mon, 29 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Sep 2025 15:45:00 +0000

Type Values Removed Values Added
References

Mon, 29 Sep 2025 15:30:00 +0000

Type Values Removed Values Added
Description The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials.
Title WEAK ENCODING FOR PASSWORD IN DEVICE SERVER CONFIGURATION
Weaknesses CWE-261
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: S21sec

Published:

Updated: 2025-09-29T15:48:58.297Z

Reserved: 2025-09-29T14:16:25.728Z

Link: CVE-2025-11155

cve-icon Vulnrichment

Updated: 2025-09-29T15:23:54.475Z

cve-icon NVD

Status : Received

Published: 2025-09-29T16:15:37.223

Modified: 2025-09-29T16:15:37.223

Link: CVE-2025-11155

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.