CVE-2025-41742
critical · 9.8Sprecher Automations SPRECON-E-C, SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys. The use of these keys allows the attacker to read, modify, and write projects and data, or to access any device via remote maintenance.
9.8
CVSS
0.5%
EPSS (exploit prob.)
39th
EPSS percentile
2025-12-02
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-1394
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sprecher-automation | sprecon-e-c_firmware | all versions |
| sprecher-automation | sprecon-e-c | all versions |
| sprecher-automation | sprecon-e-p_firmware | all versions |
| sprecher-automation | sprecon-e-p | all versions |
| sprecher-automation | sprecon-e-t3_firmware | all versions |
| sprecher-automation | sprecon-e-t3 | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-41742