7.5
CVE-2025-41737
- EPSS 0.39%
- Veröffentlicht 18.11.2025 10:18:44
- Zuletzt bearbeitet 21.11.2025 19:15:12
- Quelle info@cert.vde.com
- CVE-Watchlists
- Unerledigt
Improper access control via php endpoint
Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Metz-connect ≫ Ewio2-m Firmware Version < 2.2.0
Metz-connect ≫ Ewio2-m-bm Firmware Version < 2.2.0
Metz-connect ≫ Ewio2-bm Firmware Version < 2.2.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.39% | 0.308 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| info@cert.vde.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://certvde.com/de/advisories/VDE-2025-097