CVE-2025-41742
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-12-02
Last updated on: 2026-02-23
Assigner: CERT VDE
Description
Description
Sprecher Automations SPRECON-E-C, SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys. The use of these keys allows the attacker to read, modify, and write projects and data, or to access any device via remote maintenance.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sprecher-automation | sprecon-e-c_firmware | * |
| sprecher-automation | sprecon-e-p_firmware | * |
| sprecher-automation | sprecon-e-t3_firmware | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1394 | The product uses a default cryptographic key for potentially critical functionality. |