Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
0.0.0 (semver) before 2.2.0
affected
Default status
unaffected
0.0.0 (semver) before 2.2.0
affected
Default status
unaffected
0.0.0 (semver) before 2.2.0
affected
Description
The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.
Problem types
CWE-305 Authentication Bypass by Primary Weakness
Product status
0.0.0 (semver) before 2.2.0
0.0.0 (semver) before 2.2.0
0.0.0 (semver) before 2.2.0
Credits
Noam Moshe from Claroty Team82
Tomer Goldschmidt from Claroty Team82
References
certvde.com/de/advisories/VDE-2025-097