CVE-2025-2441
MEDIUMInitialization of a Resource with an Insecure Default - Info Disclo...
Title source: llmDescription
CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could lead to loss of confidentiality when a malicious user, having physical access, sets the radio in factory default mode where the product does not correctly initialize all data.
Scores
CVSS v3
4.6
EPSS
0.0013
EPSS Percentile
31.5%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1188
Status
published
Products (1)
Schneider Electric/Trio Q Licensed Data Radio
Versions prior to v2.7.2
Published
Apr 09, 2025
Tracked Since
Feb 18, 2026