CVE-2025-41731
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-10

Last updated on: 2025-11-12

Assigner: CERT VDE

Description
A vulnerability was identified in the password generation algorithm when accessing the debug-interface. An unauthenticated local attacker with knowledge of the password generation timeframe might be able to brute force the password in a timely manner and thus gain root access to the device if the debug interface is still enabled.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-10
Last Modified
2025-11-12
Generated
2026-06-16
AI Q&A
2025-11-10
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
jumo varitron500 *
jumo varitron500_touch *
jumo varitron300 *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-338 The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the password generation algorithm used for the debug interface. An unauthenticated local attacker who knows the timeframe in which passwords are generated could potentially brute force the password quickly and gain root access to the device if the debug interface remains enabled.

Impact Analysis

If exploited, this vulnerability can allow an unauthenticated local attacker to gain root access to the affected device, potentially leading to full control over the device, unauthorized access to sensitive data, and disruption of device operations.

Mitigation Strategies

To mitigate this vulnerability, immediately disable the debug interface if it is enabled. Restrict local access to the device to trusted users only. Monitor and limit attempts to access the debug interface to prevent brute force attacks.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-41731. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart