Description
A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates, due to improper permission handling during the runtime of services (e.g., FTP/SFTP). This access could allow the attacker to escalate privileges and modify firmware.
Problem types
CWE-732 Incorrect Permission Assignment for Critical Resource
Product status
Any version before FW13
Any version before FW13
Any version before FW13
Any version before FW13
Any version before FW13
Any version before FW13
Any version before FW13
Any version before FW13
Any version before FW13
Any version before FW13
References
certvde.com/de/advisories/VDE-2025-048