CVE-2025-40765

CRITICAL

TeleControl Server Basic V3.1 >= 3.1.2.2 < 3.1.2.3 - Unauthenticated Information Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an information disclosure vulnerability. This could allow an unauthenticated remote attacker to obtain password hashes of users and to login to and perform authenticated operations of the database service.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0012
EPSS Percentile 31.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
siemens/telecontrol_server_basic 3.1.2.2
Published Oct 14, 2025
Tracked Since Feb 18, 2026