Critical severity10.0NVD Advisory· Published Jul 1, 2025· Updated Apr 15, 2026
CVE-2025-41656
CVE-2025-41656
Description
An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.