Description
An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive information on the device. This is a result of incorrect permission assignment for the web server.
Problem types
CWE-732 Incorrect Permission Assignment for Critical Resource
Product status
0.0 (custom)
0.0 (custom)
0.0 (custom)
0.0 (custom)
Credits
Deutsche Telekom Security (DT Security)
References
certvde.com/en/advisories/VDE-2025-079/
certvde.com/en/advisories/VDE-2025-096/
janitza.csaf-tp.certvde.com/.../white/2026/vde-2025-079.json
weidmueller.csaf-tp.certvde.com/...te/2026/vde-2025-096.json