CVE-2025-41733

The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.
Configurations

No configuration.

History

18 Nov 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-18 11:15

Updated : 2025-11-18 14:06


NVD link : CVE-2025-41733

Mitre link : CVE-2025-41733

CVE.ORG link : CVE-2025-41733


JSON object : View

Products Affected

No product.

CWE
CWE-305

Authentication Bypass by Primary Weakness