Unrated severityNVD Advisory· Published Nov 18, 2025· Updated Nov 18, 2025
Possible malfunction credential injection
CVE-2025-41733
Description
The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.
Affected products
3- Range: 0.0.0
- Range: 0.0.0
- Range: 0.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.