Vulnerability Description
A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain full access to the tool and all connected devices.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://cert.vde.com/en/advisories/VDE-2025-057
- https://wago.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-057.json
FAQ
What is CVE-2025-41672?
CVE-2025-41672 is a vulnerability with a CVSS score of 10.0 (CRITICAL). A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain full access to the tool and all connected devices.
How severe is CVE-2025-41672?
CVE-2025-41672 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-41672?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.