CVE-2025-69929

CRITICAL

N3uron Web User Interface - Broken Cryptographic Algorithm

Title source: rule
STIX 2.1

Description

An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the password hashing on the client side using the MD5 algorithm over a predictable string format

Scores

CVSS v3 9.8
EPSS 0.0005
EPSS Percentile 14.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-327
Status published
Products (3)
n3uron/web_user_interface 1.21.6-230825.1720
n3uron/web_user_interface 1.21.7-240207.1047
n3uron/web_user_interface 1.21.13-250422.0858
Published Jan 29, 2026
Tracked Since Feb 18, 2026