« Volver al listado

CVE-2025-41712

Estado: AplazadaMedia (6.5)—

An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive information on the device. This is a result of incorrect permission assignment for the web server.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-41712",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-41712",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-10T15:35:50.983890Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "info@cert.vde.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "info@cert.vde.com",
      "affectedData": [
        {
          "vendor": "Janitza",
          "product": "UMG 96RM-E 24V(5222063)",
          "versions": [
            {
              "status": "affected",
              "version": "0.0",
              "versionType": "custom",
              "lessThanOrEqual": "3.13"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Janitza",
          "product": "UMG 96RM-E 230V(5222062)",
          "versions": [
            {
              "status": "affected",
              "version": "0.0",
              "versionType": "custom",
              "lessThanOrEqual": "3.13"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Weidmueller",
          "product": "ENERGY METER 750-230 (2540910000)",
          "versions": [
            {
              "status": "affected",
              "version": "0.0",
              "versionType": "custom",
              "lessThanOrEqual": "3.13"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Weidmueller",
          "product": "ENERGY METER 750-24 (2540900000)",
          "versions": [
            {
              "status": "affected",
              "version": "0.0",
              "versionType": "custom",
              "lessThanOrEqual": "3.13"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-10T18:17:56.543",
  "references": [
    {
      "url": "https://certvde.com/en/advisories/VDE-2025-079/",
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://certvde.com/en/advisories/VDE-2025-096/",
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://janitza.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-079.json",
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-096.json",
      "source": "info@cert.vde.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "info@cert.vde.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-732"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive information on the device. This is a result of incorrect permission assignment for the web server."
    },
    {
      "lang": "es",
      "value": "Un atacante remoto no autenticado que engaña a un usuario para que suba un archivo HTML manipulado puede obtener acceso a información sensible en el dispositivo. Esto es resultado de una asignación de permisos incorrecta para el servidor web."
    }
  ],
  "lastModified": "2026-06-17T09:23:01.223",
  "sourceIdentifier": "info@cert.vde.com"
}