CVE-2025-41708

HIGH

Unsecured Web Interface - Info Disclosure

Title source: llm
STIX 2.1

Description

Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn sensitive data during transmission.

Scores

CVSS v3 7.4
EPSS 0.0005
EPSS Percentile 14.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-319
Status published
Products (5)
Bender/CC612 0.0.0 - all versions
Bender/CC613 0.0.0 - all versions
Bender/ICC13xx 0.0.0 - all versions
Bender/ICC15xx 0.0.0 - all versions
Bender/ICC16xx 0.0.0 - all versions
Published Sep 08, 2025
Tracked Since Feb 18, 2026