CVE-2025-48861
BaseFortify
Publication date: 2025-08-14
Last updated on: 2025-08-14
Assigner: Robert Bosch GmbH
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| bosch | ctrlx_os_setup | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Task API endpoint of the ctrlX OS setup mechanism. It allows a remote, unauthenticated attacker to access and extract internal application data, which may include debug logs and the version information of installed applications.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure of internal application data, potentially exposing sensitive information such as debug logs and application version details. This could aid attackers in further exploiting the system or understanding its configuration.