CVE-2025-41719

HIGH

Webserver <unknown> - Memory Corruption

Title source: llm
STIX 2.1

Description

A low privileged remote attacker can corrupt the webserver users storage on the device by setting a sequence of unsupported characters which leads to deletion of all previously configured users and the creation of the default Administrator with a known default password.

Scores

CVSS v3 8.8
EPSS 0.0015
EPSS Percentile 34.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1286
Status published
Products (6)
Sauter/EY-modulo 5 ecos 5 ecos504/505 0.0 - Firmware v6.0
Sauter/EY-modulo 5 modu 5 modu524 0.0 - Firmware v6.0
Sauter/EY-modulo 5 modu 5 modu525 0.0 - Firmware v6.0
Sauter/modulo 6 devices modu612-LC 0.0.0 - Firmware v3.2.0
Sauter/modulo 6 devices modu660-AS 0.0.0 - Firmware v3.2.0
Sauter/modulo 6 devices modu680-AS 0.0.0 - Firmware v3.2.0
Published Oct 22, 2025
Tracked Since Feb 18, 2026