Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn sensitive data during transmission.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://certvde.com/de/advisories/VDE-2025-084 |
![]() ![]() |
History
Mon, 08 Sep 2025 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn sensitive data during transmission. | |
Title | Cleartext Transmission of Sensitive Data via Insecure HTTP Web Interface | |
Weaknesses | CWE-319 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-09-08T06:38:50.386Z
Reserved: 2025-04-16T11:17:48.311Z
Link: CVE-2025-41708

No data.

Status : Received
Published: 2025-09-08T07:15:36.523
Modified: 2025-09-08T07:15:36.523
Link: CVE-2025-41708

No data.

No data.