CVE-2025-36729

HIGH

Non-Primary Admin - Info Disclosure

Title source: llm
STIX 2.1

Description

A non-primary administrator user with admin rights to the web interface but without shell access permissions can display configuration of the device including the master admin password. This vulnerability also allows the user to give themselves shell access with the root gid.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0041
EPSS Percentile 32.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
RACOM/M!DGE2 4.0 - 4.6.40.106
Published Aug 26, 2025
Tracked Since Feb 18, 2026