6.8

CVE-2025-41692

Weak/Predictable root Password

A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a weak password generation algorithm.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PhoenixcontactFl Nat 2208 Firmware Version < 3.50
   PhoenixcontactFl Nat 2208 Version-
PhoenixcontactFl Nat 2008 Firmware Version < 3.50
   PhoenixcontactFl Nat 2008 Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.065
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
info@cert.vde.com 6.8 2.3 4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
CWE-916 Use of Password Hash With Insufficient Computational Effort

The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.