Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbitrary commands, potentially enabling unauthorized upload or download of configuration files and leading to full system compromise.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27994 | Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbitrary commands, potentially enabling unauthorized upload or download of configuration files and leading to full system compromise. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://certvde.com/en/advisories/VDE-2025-044/ |
|
History
Tue, 27 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 27 May 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbitrary commands, potentially enabling unauthorized upload or download of configuration files and leading to full system compromise. | |
| Title | Weidmueller: Missing Authentication Vulnerability in Industrial Ethernet Switches | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-05-27T13:26:59.857Z
Reserved: 2025-04-16T11:17:48.305Z
Link: CVE-2025-41651
Updated: 2025-05-27T13:25:47.296Z
Status : Awaiting Analysis
Published: 2025-05-27T09:15:21.380
Modified: 2025-05-28T15:01:30.720
Link: CVE-2025-41651
No data.
OpenCVE Enrichment
No data.
EUVD