Back to overview

CVE-2025-41723

CRITICAL
9.8
CVSS 3.1
Description
The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the path restriction and upload files to arbitrary locations.

Metadata

CVE ID
CVE-2025-41723
State
PUBLISHED
Assigner
CERTVDE
Reserved
2025-04-16 11:17 UTC
Published
2025-10-22 07:01 UTC
Last updated
2025-10-22 13:28 UTC
Primary CWE
CWE-35
CWE-35:Path Traversal: '.../...//'
Vendor / Product
Sauter / modulo 6 devices modu680-AS
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (6)
VendorProductPlatformVersions
Sauter EY-modulo 5 ecos 5 ecos504/505 0.0 < Firmware v6.0
Sauter EY-modulo 5 modu 5 modu524 0.0 < Firmware v6.0
Sauter EY-modulo 5 modu 5 modu525 0.0 < Firmware v6.0
Sauter modulo 6 devices modu612-LC 0.0.0 < Firmware v3.2.0
Sauter modulo 6 devices modu660-AS 0.0.0 < Firmware v3.2.0
Sauter modulo 6 devices modu680-AS 0.0.0 < Firmware v3.2.0
Weakness (CWE)
CWESourceDescription
CWE-35 cna CWE-35:Path Traversal: '.../...//'
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview