Home

Description

A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access.

PUBLISHED Reserved 2025-04-16 | Published 2026-01-27 | Updated 2026-01-27 | Assigner CERTVDE




HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-420 Unprotected Alternate Channel

Product status

Default status
unaffected

0.0.0 (semver) before 2.5.3
affected

Default status
unaffected

0.0.0 (semver) before 1.7.0.0
affected

Default status
unaffected

0.0.0 (semver) before 0.0.5
affected

Credits

Diego Giubertoni from Nozomi Networks finder

References

certvde.com/de/advisories/VDE-2025-092

cve.org (CVE-2025-41727)

nvd.nist.gov (CVE-2025-41727)

Download JSON