CVE-2025-41712
MEDIUM EPSS 30.7%
Published Mar 10, 20263mo ago · Modified Jun 17, 20261w ago
6.5 CVSS 3.1
Published Mar 10, 2026 3mo ago
Last Modified Jun 17, 2026 1w ago
Description
An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive information on the device. This is a result of incorrect permission assignment for the web server.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality High
Integrity None
Availability None
Threat Intelligence
EPSS Exploit Probability
30.7% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-732
References 4
- certvde.com https://certvde.com/en/advisories/VDE-2025-079/
- certvde.com https://certvde.com/en/advisories/VDE-2025-096/
- janitza.csaf-tp.certvde.com https://janitza.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-079.json
- weidmueller.csaf-tp.certvde.com https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-096.json
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.