CVE-2020-7525

HIGH

Schneider Electric spaceLYnk and Wiser for KNX Firmware < 2.5.1 - Unauthenticated Password Brute-Force

Title source: llm
STIX 2.1

Description

Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute force is used.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0025
EPSS Percentile 48.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-307
Status published
Products (2)
schneider-electric/spacelynk_firmware < 2.5.1
schneider-electric/wiser_for_knx_firmware < 2.5.1
Published Aug 31, 2020
Tracked Since Feb 18, 2026