CVE-2025-41722

HIGH

wsc server - Info Disclosure

Title source: llm

Description

The wsc server uses a hard-coded certificate to check the authenticity of SOAP messages. An unauthenticated remote attacker can extract private keys from the Software of the affected devices.

Scores

CVSS v3 7.5
EPSS 0.0003
EPSS Percentile 8.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-798
Status draft

Timeline

Published Oct 22, 2025
Tracked Since Feb 18, 2026