The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 18 Nov 2025 10:30:00 +0000

Type Values Removed Values Added
Description The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.
Title Possible malfunction credential injection
Weaknesses CWE-305
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2025-11-18T10:17:46.326Z

Reserved: 2025-04-16T11:17:48.319Z

Link: CVE-2025-41733

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-18T11:15:46.700

Modified: 2025-11-18T11:15:46.700

Link: CVE-2025-41733

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.