CVE-2025-41672

CRITICAL

Default Certificates - Unauthenticated RCE

Title source: llm
STIX 2.1

Description

A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain full access to the tool and all connected devices.

Scores

CVSS v3 10.0
EPSS 0.0016
EPSS Percentile 36.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-1188
Status published
Products (1)
WAGO/Wago Device Sphere 1.0.0
Published Jul 07, 2025
Tracked Since Feb 18, 2026