Home
HIGH: 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
0.0.0 (semver) before 1.7.3
affected
Default status
unaffected
0.0.0 (semver) before 1.7.3
affected
Default status
unaffected
0.0.0 (semver) before 1.7.3
affected
Default status
unaffected
0.0.0 (semver) before 1.7.3
affected
Description
An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing authentication.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
0.0.0 (semver) before 1.7.3
0.0.0 (semver) before 1.7.3
0.0.0 (semver) before 1.7.3
0.0.0 (semver) before 1.7.3
Credits
HT3 Labs
References
certvde.com/de/advisories/VDE-2025-019