Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19648 | An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default. |
| Link | Providers |
|---|---|
| https://certvde.com/en/advisories/VDE-2025-045 |
|
Tue, 01 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 01 Jul 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default. | |
| Title | Pilz: Missing Authentication in Node-RED integration | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-07-01T14:32:08.516Z
Reserved: 2025-04-16T11:17:48.306Z
Link: CVE-2025-41656
Updated: 2025-07-01T14:32:03.656Z
Status : Deferred
Published: 2025-07-01T08:15:24.443
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-41656
No data.
OpenCVE Enrichment
Updated: 2025-07-14T23:06:26Z
EUVD