Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27114 | A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates, due to improper permission handling during the runtime of services (e.g., FTP/SFTP). This access could allow the attacker to escalate privileges and modify firmware. |
| Link | Providers |
|---|---|
| https://certvde.com/de/advisories/VDE-2025-048 |
|
Mon, 08 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wago
Wago 0750-0362 Wago 0750-0363 Wago 0750-0366 |
|
| Vendors & Products |
Wago
Wago 0750-0362 Wago 0750-0363 Wago 0750-0366 |
Mon, 08 Sep 2025 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates, due to improper permission handling during the runtime of services (e.g., FTP/SFTP). This access could allow the attacker to escalate privileges and modify firmware. | |
| Title | Improper Permission Handling Enables Unauthorized Access to Firmware and Certificates | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-09-08T16:03:08.365Z
Reserved: 2025-04-16T11:17:48.307Z
Link: CVE-2025-41664
Updated: 2025-09-08T16:02:53.085Z
Status : Deferred
Published: 2025-09-08T07:15:36.013
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-41664
No data.
OpenCVE Enrichment
Updated: 2025-09-08T15:17:26Z
EUVD