← All CVEs

CVE-2025-41648

critical · 9.8

An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possible to access and change all available settings of the IndustrialPI.

9.8
CVSS
0.7%
EPSS (exploit prob.)
52nd
EPSS percentile
2025-07-01
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-704

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-41648