VYPR
Low severity2.2NVD Advisory· Published Dec 4, 2025· Updated Jun 17, 2026

CVE-2025-12997

CVE-2025-12997

Description

Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would expose sensitive user information. This issue affects CareLink Network: before December 4, 2025.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:medtronic:carelink_network:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:medtronic:carelink_network:*:*:*:*:*:*:*:*range: <2025-12-04
    • (no CPE)range: <2025-12-04
    • (no CPE)range: 0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.