CVE-2025-14295
Unknown Unknown - Not Provided
Recoverable Password Storage Vulnerability in WebCTRL and i-Vu

Publication date: 2026-01-22

Last updated on: 2026-01-22

Assigner: Carrier Global Corporation

Description
Storing Passwords in a Recoverable Format vulnerability in Automated Logic WebCTRL on Windows, Carrier i-Vu on Windows. Storing Passwords in a Recoverable Format vulnerability (CWE-257) in the Web session management component allows an attacker to access stored passwords in a recoverable format which makes them subject to password reuse attacks by malicious users.This issue affects WebCTRL: from 6.0 through 9.0; i-Vu: from 6.0 through 9.0.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-22
Last Modified
2026-01-22
Generated
2026-05-07
AI Q&A
2026-01-22
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
automated_logic webctrl From 6.0 (inc) to 9.0 (inc)
carrier i-vu From 6.0 (inc) to 9.0 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-257 The storage of passwords in a recoverable format makes them subject to password reuse attacks by malicious users. In fact, it should be noted that recoverable encrypted passwords provide no significant benefit over plaintext passwords since they are subject not only to reuse by malicious attackers but also by malicious insiders. If a system administrator can recover a password directly, or use a brute force search on the available information, the administrator can use the password on other accounts.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability involves storing passwords in a recoverable format within the Web session management component of Automated Logic WebCTRL and Carrier i-Vu on Windows. Because passwords are stored in a way that they can be retrieved, an attacker who gains access to this storage can obtain the passwords and potentially reuse them maliciously.


How can this vulnerability impact me? :

The vulnerability can allow attackers to access stored passwords in a recoverable format, which can lead to password reuse attacks. This compromises the security of user accounts and systems, potentially allowing unauthorized access and further exploitation.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart