Home

Description

The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.

PUBLISHED Reserved 2025-04-16 | Published 2025-11-18 | Updated 2025-11-18 | Assigner CERTVDE




CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-305 Authentication Bypass by Primary Weakness

Product status

Default status
unaffected

0.0.0 (semver) before 2.2.0
affected

Default status
unaffected

0.0.0 (semver) before 2.2.0
affected

Default status
unaffected

0.0.0 (semver) before 2.2.0
affected

Credits

Noam Moshe from Claroty Team82 finder

Tomer Goldschmidt from Claroty Team82 finder

References

certvde.com/de/advisories/VDE-2025-097

cve.org (CVE-2025-41733)

nvd.nist.gov (CVE-2025-41733)

Download JSON