CVE-2025-41692

CWE-9163 documents3 sources
Severity
6.8MEDIUM
EPSS
0.0%
top 91.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9

Description

A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a weak password generation algorithm.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:NExploitability: 2.3 | Impact: 4.0

Affected Packages138 packages

CVEListV5phoenix_contact/fl_nat_20080.0.03.50
CVEListV5phoenix_contact/fl_nat_22080.0.03.50
CVEListV5phoenix_contact/fl_switch_20050.0.03.50
CVEListV5phoenix_contact/fl_switch_20080.0.03.50
CVEListV5phoenix_contact/fl_switch_20160.0.03.50

🔴Vulnerability Details

2
GHSA
GHSA-5q5j-x9p3-cg4x: A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a we2025-12-09
CVEList
Weak/Predictable root Password2025-12-09
CVE-2025-41692 (MEDIUM CVSS 6.8) | A high privileged remote attacker w | cvebase.io